PSReadLine ConsoleHost_history.txt Forensics
What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.
TL;DR. PSReadLine saves every command typed at an interactive console to ConsoleHost_history.txt — one line each, no timestamps, per user, surviving reboots. It is a goldmine for what a person typed, but records only interactive console input and gives you order, not time. Open the parser to read it beside the event logs.
Where it lives and what it holds
PSReadLine (shipped in-box since PowerShell 5 / Windows 10) keeps a history file at:
C:\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
The name is <HostName>_history.txt; ConsoleHost is the normal powershell.exe console. It appends one line per accepted command. A multi-line command is saved with a trailing backtick on every line but the last, so the parser rejoins those into one entry. Because it is per user under AppData\Roaming, it is attributed to whoever's profile it sits in — keep the Users\<name>\ path when you collect it. See PSReadLine.
No timestamps — order only
The file carries no times at all. That has two consequences. First, its chronology is only the order of lines; to place a command in time you must correlate it with a timestamped 4104 or 800 event, or a transcript. Second, the file persists across reboots and profile logons, so a line can be weeks or months older than the earliest event in your logs. Treat it as a record of intent and technique, corroborated elsewhere for timing.
Limits worth stating
- Interactive only. Commands run from a
.ps1, a scheduled task, WinRM or a custom host that is not the console are not written here. - Attacker-controlled. History can be cleared (
Clear-Historyclears the session; deleting or truncating the file removes it entirely) — the parser flags history-clearing commands it sees. - Not proof of success. It records what was typed, including typos and abandoned commands, not what succeeded.
Use it in a case
Load the history file alongside the event logs and transcripts so a typed command lines up with its logged execution. The parser decodes any encoded command on a history line and flags download cradles, Defender and AMSI tampering, and log clearing. Analyze it in your browser.
FAQ
Where is the PowerShell history file?
PSReadLine writes it to C:\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt, one per user. Other hosts use <HostName>_history.txt.
Does it have timestamps?
No. PSReadLine appends one line per command with no time. The order of lines is the only chronology, and the file can be far older than the event logs.
What does it capture?
Only interactive input typed at a console host, per user, across sessions and reboots. It does not capture scripts, scheduled tasks or non-console runspaces.