Posts tagged: #dfir
Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.
How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.
What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.
How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.
Acquire the PowerShell event logs, PSReadLine history and transcripts from a live host, a triage collection or a disk image — with copy-paste commands and the gotchas.
A map of PowerShell's forensic event IDs across the Operational and classic Windows PowerShell logs — 4104, 4103, 400, 403, 600, 800 — and what each one proves.
What event ID 4104 records, how Windows splits long script blocks across events, why warning-level blocks appear without full logging, and how to read it in a case.