PowerShell Core Concepts
PowerShell is not just a command-line tool; its design philosophy, functional architecture, and usage differ significantly from traditional shells.
1. Cmdlet: The Smallest Command Unit
What is a Cmdlet?
A Cmdlet (pronouncedcommand-let) is the most basic command unit in PowerShell. Cmdlets are .NET-based classes that return one or more.NET objects。
Naming Convention: Verb-Noun
Every Cmdlet follows theverb-nounnaming convention, for example:
| Cmdlet | Meaning |
|---|---|
Get-Process |
Get process information |
Set-Item |
Set the value of a resource item |
Remove-Item |
Delete files, registry keys, etc. |
New-User |
Create a new user (if the AD module is installed) |
PowerShell ships with hundreds of Cmdlets, and third-party modules can define many more.
Example
Get-Service Get-ChildItem -Path C:\Windows
You can also useGet-Commandto view all available Cmdlets:
Get-Command -CommandType Cmdlet
2. Object Pipeline
What's the difference from UNIX/Linux pipes?
In traditional shells, the pipe (|) passes text strings. In PowerShell, however,the pipeline passes complete .NET objects。
This means you can preserve structured data (properties, methods) for further processing.
Example: Filter processes by CPU usage
Get-Process | Where-Object { $_.CPU -gt 100 } | Select-Object Name, CPU
In the above command:
Get-ProcessGet all processes (returns objects)Where-ObjectFilter processes with CPU usage greater than 100Select-ObjectOutput only theNameandCPUfield
The beauty of piping objects
You don't need to use tools likeawk、cut、grepto "parse" the output; instead, you work directly with object properties.
3. Providers and PSDrive: Resource Drive Abstraction
PowerShell provides a unified way to access resources:the Provider model, which maps various resources to virtual drives (PSDrive), just likeC:operating a drive.
Common Provider types
| Provider | Example drive | Description |
|---|---|---|
| FileSystem | C:, D: |
Local file system |
| Registry | HKLM:, HKCU: |
Windows Registry |
| Environment | Env: |
Environment variables |
| Certificate | Cert: |
Certificate store |
| Function | Function: |
Functions in the current session |
| Variable | Variable: |
Currently defined variables |
| Alias | Alias: |
Command aliases |
Example: Working with the registry
Get-ChildItem HKLM:\Software\Microsoft
Browse the registry just like browsing folders.
4. Scripts and Modules: Organization and Reuse
Scripts (.ps1)
- PowerShell scripts are text files with the
.ps1extension - They contain a series of commands, flow control, functions, etc.
Modules (.psm1 / .psd1)
A module is a reusable functional unit in PowerShell. It can be:
- a
.psm1file (module script) - a folder containing a
.psd1manifest (advanced module)
Modules support:
- Auto-loading(automatically loaded when its functions are used)
- Versioning
- Dependency declarations
View all modules in the system:
Get-Module -ListAvailable
Import a module:
Import-Module Az
5. Execution Policy
To prevent malicious scripts from running, PowerShell introduced theexecution policy(Execution Policy), which restricts.ps1the execution behavior of script files.
Common policy types
| Policy | Meaning |
|---|---|
| Restricted | Default; no scripts are allowed to run |
| RemoteSigned | Allows local scripts to run; remote scripts must be signed |
| AllSigned | All scripts must be signed |
| Bypass | Unrestricted; not recommended for production |
Setting the execution policy
Set-ExecutionPolicy RemoteSigned -Scope CurrentUser
⚠️ Note: The execution policy only affects script files; it does not restrict manually entered commands.
6. Remote Management (PowerShell Remoting)
PowerShell Remoting supports connecting to another computer remotely and executing commands via theWS-MAN (based on WinRM)orSSHprotocol.
Enabling WinRM (on Windows)
Enable-PSRemoting -Force
Common commands
# 建立远程会话
Enter-PSSession -ComputerName Server01
# 批量执行命令
Invoke-Command -ComputerName Server01,Server02 -ScriptBlock { Get-Service }
Cross-platform remoting with SSH support
Enter-PSSession -HostName linux01 -User user1 -SSHTransport
7. Desired State Configuration (DSC)
DSC (Desired State Configuration) is PowerShell'sdeclarative configuration platform, used to define the "desired state" of a system.
It allows you to:
- Define resource states with configuration scripts (e.g., a service should be running, a file should exist)
- Automatically configure the machine to that state
- Detect drift and automatically remediate it
How to use it
- Write a configuration file (
.ps1) - Compile it into a MOF file
- Deploy using Push or Pull mode
DSC is especially useful for large-scale server configuration, compliance checks, and automated deployment.
8. Command Discovery and Help System
PowerShell provides a rich help system that lets you easily explore commands:
Get-Help Get-Process: View command helpGet-Command: List all commandsGet-Member: View object properties and methodsGet-Help about_*: View built-in knowledge documents (such asabout_Execution_Policies)
Example: Viewing object structure
Get-Process | Get-Member
Summary
| Concept | Keyword | Brief description | |
|---|---|---|---|
| Cmdlet | verb-noun |
Smallest execution unit, based on .NET | |
| Pipeline | ` | ` | Passes objects rather than text |
| Provider | FileSystem, Env: |
Unified access to various resources | |
| Module | .psm1, .psd1 |
Organizes reusable command collections | |
| Execution policy | Set-ExecutionPolicy |
Controls script execution permissions | |
| Remote management | Enter-PSSession |
Execute commands remotely | |
| DSC | Configuration |
Declarative system configuration platform | |
| Help system | Get-Help |
Built-in documentation system |