Worthwhile reading over at InfosecIsland:
A new attack vector through PowerShell has been released to allow users to deliver whatever payload they want to in both a bind and reverse type scenario and drop any executable.
Now if you are on a penetration testing mission, you start by running an nmap search for the live Windows hosts on the network, basically with 1433 active port (Mssql).
https://www.infosecisland.com/blogview/10518-Attacking-Windows-Operating-Systems-with-PowerShell.html