This document introduces the use of PowerShell for security assessments, emphasizing its advantages in security auditing by enabling 'living off the land' practices. It outlines the capabilities of PowerShell as a scripting language and command line tool, detailing its functionality, cmdlets, and modules relevant to assessing the security of Microsoft systems. Additionally, it provides a step-by-step approach for conducting security assessments, highlighting key areas such as governance, registry settings, and service-specific cmdlets.