Skip to content

A–Z

Glossary

Plain-language definitions of the PowerShell forensics terms used across the blog.

PowerShell transcription
A feature that writes a full text record of a PowerShell session — input and output — to a PowerShell_transcript file, with local timestamps.
PSReadLine
The PowerShell console line editor that saves interactive command history to ConsoleHost_history.txt, without timestamps.
AMSI (Antimalware Scan Interface)
A Windows interface that lets antivirus scan script content at runtime, including PowerShell; attackers try to disable it in-process.
Download cradle
A short PowerShell snippet that fetches code from a remote URL and runs it in memory, without writing a file to disk.
Encoded command (-EncodedCommand)
A PowerShell parameter that takes a Base64 string of UTF-16LE command text, used to pass scripts that survive quoting — and to obscure intent.
Execution policy bypass
Flags such as -ExecutionPolicy Bypass that turn off PowerShell's script-running safety check — a near-ubiquitous marker in malicious launchers.
Invoke-Expression (IEX)
A PowerShell cmdlet that runs a string as code — the execution half of most download cradles and obfuscation chains.
PowerShell downgrade attack
Launching PowerShell version 2 to escape the script block logging and AMSI that only exist in version 5.
Module Logging (4103)
PowerShell pipeline execution logging: event ID 4103 records commands and bound parameters as they run.
Windows PowerShell classic log
The original Windows PowerShell.evtx log holding engine and provider lifecycle (400/403/600) and pipeline execution (800) events.
Event ID 4104
The PowerShell Script Block Logging event: one block of compiled code, identified by ScriptBlockId and numbered MessageNumber of MessageTotal.
Script Block Logging
A PowerShell 5 feature that records the source of every script block the engine compiles, after de-obfuscation, to event ID 4104.