<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PowerShell Parser — Blog</title>
    <link>https://www.powershellparser.com/de/blog</link>
    <description>Latest from Blog</description>
    <language>de</language>
    <lastBuildDate>Tue, 29 Sep 2026 14:11:26 GMT</lastBuildDate>
    <atom:link href="https://www.powershellparser.com/de/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>PowerShell-Protokolle im Browser analysieren</title>
      <link>https://www.powershellparser.com/de/blog/analyze-powershell-logs-in-browser</link>
      <guid isPermaLink="true">https://www.powershellparser.com/de/blog/analyze-powershell-logs-in-browser</guid>
      <description>Schritt für Schritt: PowerShell-.evtx-Protokolle, PSReadLine-Verlauf und Transkripte in einem kostenlosen Browser-Viewer öffnen, Skriptblöcke zusammensetzen, kodierte Befehle dekodieren und als CSV oder JSON exportieren.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Forensik von PowerShell-Transkripten: Das Transkript lesen</title>
      <link>https://www.powershellparser.com/de/blog/powershell-transcription-forensics</link>
      <guid isPermaLink="true">https://www.powershellparser.com/de/blog/powershell-transcription-forensics</guid>
      <description>Wie PowerShell-Transkripte aufgebaut sind, was der Header aufzeichnet, wie Befehlszeitstempel mit -IncludeInvocationHeader funktionieren und wie man Transkripte untersucht.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Forensik von PSReadLine ConsoleHost_history.txt</title>
      <link>https://www.powershellparser.com/de/blog/psreadline-consolehost-history-forensics</link>
      <guid isPermaLink="true">https://www.powershellparser.com/de/blog/psreadline-consolehost-history-forensics</guid>
      <description>Was die PSReadLine-Verlaufsdatei aufzeichnet, wo sie liegt, warum sie keine Zeitstempel hat und wie man sie – samt ihren Grenzen – in einer Untersuchung nutzt.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PowerShell -EncodedCommand und Obfuskation dekodieren</title>
      <link>https://www.powershellparser.com/de/blog/decode-powershell-encoded-command</link>
      <guid isPermaLink="true">https://www.powershellparser.com/de/blog/decode-powershell-encoded-command</guid>
      <description>Wie -EncodedCommand und gängige PowerShell-Obfuskation funktionieren – base64/UTF-16LE, gzip/deflate, Zeichencodes, Verkettung, der Formatoperator und Backticks – und wie man sie gefahrlos dekodiert.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PowerShell-Protokolle, Transkripte und Verlauf sichern</title>
      <link>https://www.powershellparser.com/de/blog/collect-powershell-logs-transcripts-history</link>
      <guid isPermaLink="true">https://www.powershellparser.com/de/blog/collect-powershell-logs-transcripts-history</guid>
      <description>PowerShell-Ereignisprotokolle, PSReadLine-Verlauf und Transkripte von einem Live-System, aus einer Triage-Sammlung oder einem Datenträgerabbild sichern – mit kopierfertigen Befehlen und den typischen Fallstricken.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PowerShell-Ereignisprotokolle in der Forensik: Alle relevanten IDs</title>
      <link>https://www.powershellparser.com/de/blog/powershell-event-logs-forensics-guide</link>
      <guid isPermaLink="true">https://www.powershellparser.com/de/blog/powershell-event-logs-forensics-guide</guid>
      <description>Eine Übersicht der forensisch relevanten PowerShell-Ereignis-IDs im Operational-Protokoll und im klassischen Windows-PowerShell-Protokoll – 4104, 4103, 400, 403, 600, 800 – und was jede einzelne belegt.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PowerShell-Skriptblockprotokollierung (4104): Ein Forensik-Leitfaden</title>
      <link>https://www.powershellparser.com/de/blog/powershell-script-block-logging-4104-forensics</link>
      <guid isPermaLink="true">https://www.powershellparser.com/de/blog/powershell-script-block-logging-4104-forensics</guid>
      <description>Was Ereignis-ID 4104 aufzeichnet, wie Windows lange Skriptblöcke auf mehrere Ereignisse verteilt, warum Blöcke auf Warnstufe auch ohne vollständige Protokollierung erscheinen und wie man sie in einem Fall auswertet.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>