Skip to content

PowerShell Transcription Forensics: Reading the Transcript

How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.

Published on 2 min read

TL;DR. A transcript is a text record of a whole PowerShell session — input and output — written by Start-Transcript or the transcription policy to PowerShell_transcript.<computer>.<random>.<timestamp>.txt. The header holds the start time, user, machine, host application and PID; with -IncludeInvocationHeader each command gets its own start time. All times are the host's local clock. Open the parser to read sessions and commands as a timeline.

Structure

Transcription is enabled by Start-Transcript or Group Policy ("Turn on PowerShell Transcription"), which can force it for every session and set an OutputDirectory (Microsoft: about_Logging_Windows). A file begins with a header between rows of asterisks:

**********************
Windows PowerShell transcript start
Start time: 20260914104500
Username: FIN-WKS-07\svc_backup
Machine: FIN-WKS-07 (Microsoft Windows NT 10.0.19045.0)
Host Application: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Process ID: 4242
PSVersion: 5.1.19041.4648
**********************

Then each prompt line (PS C:\Users\svc_backup>) is followed by the command and its output. With -IncludeInvocationHeader, a Command start time: block precedes each command — the parser attaches that time to the command; without it, commands inherit the session start time (shown as approximate). See PowerShell transcription.

Local time, no zone

Every timestamp in a transcript — Start time, End time, Command start time — is the host's local wall clock, formatted yyyyMMddHHmmss, with no zone. When you correlate a transcript with the UTC event logs, you must know the machine's time zone. The parser shows transcript times as local (tagged) and never silently converts them.

What transcripts add

Unlike the event logs, a transcript captures output, so you can see what a command returned — a directory listing, a file's contents, an error. That context often resolves whether an action succeeded. The parser decodes any encoded command in a transcript line and flags cradles and tampering, and reads multi-session files (a file can hold several transcript start/transcript end pairs). A missing transcript end footer means the session was cut short or the file is truncated — the parser warns you.

Read transcripts beside PSReadLine history and the logs; analyze the whole set in your browser.

FAQ

Where are PowerShell transcripts saved?

By default to the user's Documents folder as PowerShell_transcript.<computer>.<random>.<timestamp>.txt, or to the OutputDirectory set by the transcription policy. Each session is one file.

Do transcripts have timestamps?

The header has a Start time and End time, and with -IncludeInvocationHeader each command gets a Command start time. All times are the host's local clock, with no time zone recorded.

What does a transcript contain that logs do not?

The full input and output of a session as the user saw it, including command results — context the event logs do not capture.

Related articles

Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.
What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.
How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.