Skip to content

PSReadLine ConsoleHost_history.txt Forensics

What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.

Published on 3 min read

TL;DR. PSReadLine saves every command typed at an interactive console to ConsoleHost_history.txt — one line each, no timestamps, per user, surviving reboots. It is a goldmine for what a person typed, but records only interactive console input and gives you order, not time. Open the parser to read it beside the event logs.

Where it lives and what it holds

PSReadLine (shipped in-box since PowerShell 5 / Windows 10) keeps a history file at:

C:\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt

The name is <HostName>_history.txt; ConsoleHost is the normal powershell.exe console. It appends one line per accepted command. A multi-line command is saved with a trailing backtick on every line but the last, so the parser rejoins those into one entry. Because it is per user under AppData\Roaming, it is attributed to whoever's profile it sits in — keep the Users\<name>\ path when you collect it. See PSReadLine.

No timestamps — order only

The file carries no times at all. That has two consequences. First, its chronology is only the order of lines; to place a command in time you must correlate it with a timestamped 4104 or 800 event, or a transcript. Second, the file persists across reboots and profile logons, so a line can be weeks or months older than the earliest event in your logs. Treat it as a record of intent and technique, corroborated elsewhere for timing.

Limits worth stating

  • Interactive only. Commands run from a .ps1, a scheduled task, WinRM or a custom host that is not the console are not written here.
  • Attacker-controlled. History can be cleared (Clear-History clears the session; deleting or truncating the file removes it entirely) — the parser flags history-clearing commands it sees.
  • Not proof of success. It records what was typed, including typos and abandoned commands, not what succeeded.

Use it in a case

Load the history file alongside the event logs and transcripts so a typed command lines up with its logged execution. The parser decodes any encoded command on a history line and flags download cradles, Defender and AMSI tampering, and log clearing. Analyze it in your browser.

FAQ

Where is the PowerShell history file?

PSReadLine writes it to C:\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt, one per user. Other hosts use <HostName>_history.txt.

Does it have timestamps?

No. PSReadLine appends one line per command with no time. The order of lines is the only chronology, and the file can be far older than the event logs.

What does it capture?

Only interactive input typed at a console host, per user, across sessions and reboots. It does not capture scripts, scheduled tasks or non-console runspaces.

Related articles

Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.
How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.
How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.