Análisis forense, PowerShell PowerShell (Get-WmiObject -Class Win32_OperatingSystem).LastBootupTime 1 (Get-WmiObject -Class Win32_OperatingSystem).LastBootupTime