What PowerShell logs record
PowerShell writes several independent trails. Script Block Logging (event 4104, in the Microsoft-Windows-PowerShell/Operational log) records the actual code that ran — the deobfuscated script text, split across several 4104 events for long blocks. Module logging (4103) records pipeline execution details. The classic "Windows PowerShell" log records engine and provider lifecycle (400/403/600) and, with a policy, pipeline execution (800).
Outside the event logs, PSReadLine keeps a plain-text history of everything typed at an interactive console, and Start-Transcript (or the transcription policy) writes a full transcript of a session to a text file. Together they are one of the richest records of what an operator — or an intruder — did on a Windows host.
Where it is stored
- C:\Windows\System32\winevt\Logs\Microsoft-Windows-PowerShell%4Operational.evtx — Script Block Logging (4104) and module logging (4103).
- C:\Windows\System32\winevt\Logs\Windows PowerShell.evtx — classic engine/provider/pipeline events (400/403/600/800).
- C:\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt — interactive command history, per user.
- C:\Users\<user>\Documents\PowerShell_transcript.<host>.<random>.<timestamp>.txt — transcripts, when enabled.
Why it matters in an investigation
- Script Block Logging captures the code as PowerShell saw it, so an -EncodedCommand or an obfuscated one-liner is recorded in its expanded form — this parser also decodes the encoded and compressed layers for you.
- The reassembly of 4104 by ScriptBlockId and MessageNumber/MessageTotal rebuilds long scripts that Windows split across many events, and flags any missing part.
- PSReadLine history and transcripts capture interactive activity that may never touch a script file, including typos and abandoned commands.
- Findings point out download cradles, AMSI/ETW bypasses, logging and Defender tampering, execution-policy bypass, hidden windows, engine downgrades and common obfuscation — as leads to verify, not verdicts.
Limitations
- Script Block Logging is off by default; without it you may only see Warning-level blocks Windows flagged on its own, plus the classic log and history.
- PSReadLine history has no timestamps: its order is the only chronology, and it can be far older than the logs.
- Transcript times are the host's local clock with no zone; event-log times are UTC.
- Logs roll over and can be cleared; this tool flags clearing commands but cannot recover events already removed.
How to get the files
- Export the two PowerShell event logs with wevtutil epl (or collect every .evtx with KAPE / Velociraptor), and copy each user's PSReadLine history and transcripts.
- The EventLog service keeps logs open on a live host, so use an export rather than a plain copy.
- Keep the Users\<name>\ folder structure so history and transcripts are attributed to the right account.
FAQ
Are my files uploaded anywhere?
No. The parser — including the .evtx reader — is Rust compiled to WebAssembly and runs in a Web Worker in your browser. There is no upload endpoint, and nothing in a script is ever executed.
Does it decode -EncodedCommand and obfuscated scripts?
Yes. Base64 -EncodedCommand is decoded from UTF-16LE, and further layers — gzip/deflate payloads, [char] codes, string concatenation, the -f format operator and backtick escaping — are unwound and shown as inert text. It never runs the script.
How does it rebuild a script block that spans several events?
Windows splits a long script block across several 4104 events sharing a ScriptBlockId, each carrying MessageNumber of MessageTotal. The parser groups by ScriptBlockId, orders by MessageNumber, concatenates the text and flags any missing part.
What if Script Block Logging was turned off?
You will still see the classic Windows PowerShell log (engine and pipeline events), PSReadLine history and any transcripts. Windows also logs script blocks it considers suspicious at Warning level even when full logging is off, and those are captured too.
Which files should I collect?
Microsoft-Windows-PowerShell%4Operational.evtx and Windows PowerShell.evtx from winevt\Logs, each user's ConsoleHost_history.txt, and any PowerShell_transcript.*.txt. The built-in collection guide gives one-command exports.