<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PowerShell Parser — Blog</title>
    <link>https://www.powershellparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Tue, 29 Sep 2026 12:42:17 GMT</lastBuildDate>
    <atom:link href="https://www.powershellparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>How to Analyze PowerShell Logs in Your Browser</title>
      <link>https://www.powershellparser.com/en/blog/analyze-powershell-logs-in-browser</link>
      <guid isPermaLink="true">https://www.powershellparser.com/en/blog/analyze-powershell-logs-in-browser</guid>
      <description>Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PowerShell Transcription Forensics: Reading the Transcript</title>
      <link>https://www.powershellparser.com/en/blog/powershell-transcription-forensics</link>
      <guid isPermaLink="true">https://www.powershellparser.com/en/blog/powershell-transcription-forensics</guid>
      <description>How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PSReadLine ConsoleHost_history.txt Forensics</title>
      <link>https://www.powershellparser.com/en/blog/psreadline-consolehost-history-forensics</link>
      <guid isPermaLink="true">https://www.powershellparser.com/en/blog/psreadline-consolehost-history-forensics</guid>
      <description>What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Decoding PowerShell -EncodedCommand and Obfuscation</title>
      <link>https://www.powershellparser.com/en/blog/decode-powershell-encoded-command</link>
      <guid isPermaLink="true">https://www.powershellparser.com/en/blog/decode-powershell-encoded-command</guid>
      <description>How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Collect PowerShell Logs, Transcripts and History</title>
      <link>https://www.powershellparser.com/en/blog/collect-powershell-logs-transcripts-history</link>
      <guid isPermaLink="true">https://www.powershellparser.com/en/blog/collect-powershell-logs-transcripts-history</guid>
      <description>Acquire the PowerShell event logs, PSReadLine history and transcripts from a live host, a triage collection or a disk image — with copy-paste commands and the gotchas.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PowerShell Event Logs for Forensics: Every ID That Matters</title>
      <link>https://www.powershellparser.com/en/blog/powershell-event-logs-forensics-guide</link>
      <guid isPermaLink="true">https://www.powershellparser.com/en/blog/powershell-event-logs-forensics-guide</guid>
      <description>A map of PowerShell&apos;s forensic event IDs across the Operational and classic Windows PowerShell logs — 4104, 4103, 400, 403, 600, 800 — and what each one proves.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PowerShell Script Block Logging (4104): A Forensics Guide</title>
      <link>https://www.powershellparser.com/en/blog/powershell-script-block-logging-4104-forensics</link>
      <guid isPermaLink="true">https://www.powershellparser.com/en/blog/powershell-script-block-logging-4104-forensics</guid>
      <description>What event ID 4104 records, how Windows splits long script blocks across events, why warning-level blocks appear without full logging, and how to read it in a case.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>