Skip to content

How to Analyze PowerShell Logs in Your Browser

Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.

Published on 2 min read

TL;DR. Open the PowerShell Parser, drop your .evtx logs, ConsoleHost_history.txt and PowerShell_transcript.*.txt (or a whole KAPE/Velociraptor ZIP), and it reassembles script blocks, decodes encoded commands, flags suspicious activity and exports CSV/JSON. Everything runs locally in WebAssembly; nothing is uploaded and nothing is executed.

Before you start

You need the collected evidence. If you do not have it yet, follow how to collect PowerShell logs, transcripts and history. Keep the Users\<name>\ folders so history and transcripts are attributed to the right account.

Load the files

Open the home page and drop the files, a folder, or a triage ZIP on the drop zone — or use Choose files / Choose a folder. The parser recognises the two PowerShell event logs by name, *_history.txt and PowerShell_transcript.*.txt, and ignores unrelated files in a collection. Each file is parsed by Rust compiled to WebAssembly, inside a Web Worker.

Read the workspace

The counters show accounts, total entries, script blocks, high-severity findings, flagged entries and partial blocks. Warnings call out missing script-block parts, truncated transcripts and logs with no PowerShell events. The table merges every source into one timeline; the type filter narrows it to script blocks, the classic log, module logging, history or transcripts.

Inspect and decode

Open any row to see the reassembled 4104 block, its findings (download cradle, AMSI bypass, logging or Defender tampering, execution-policy bypass, hidden window, downgrade), and the de-obfuscation layers that turn an encoded blob into readable text. Paste anything ad-hoc into the de-obfuscation view. Nothing is ever executed.

Time range and export

Apply a custom time range (UTC for event logs; transcript/history times are shown as local), then export the filtered rows to CSV or JSON — the range is written into the file name for your case notes.

FAQ

Is anything uploaded?

No. The parser and its .evtx reader are Rust compiled to WebAssembly, running in a Web Worker in your browser. There is no upload endpoint.

Does it run the scripts it decodes?

Never. Decoding is a pure text transformation. The tool reads and reveals; it does not execute.

What files can I drop?

Microsoft-Windows-PowerShell%4Operational.evtx, Windows PowerShell.evtx (and the PowerShell 7 log), ConsoleHost_history.txt and PowerShell_transcript.*.txt — individually, in a folder, or in a KAPE/Velociraptor ZIP.

Related articles

How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.
What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.
How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.