A–Z
Glossary
Plain-language definitions of the PowerShell forensics terms used across the blog.
- PowerShell transcription
- A feature that writes a full text record of a PowerShell session — input and output — to a PowerShell_transcript file, with local timestamps.
- PSReadLine
- The PowerShell console line editor that saves interactive command history to ConsoleHost_history.txt, without timestamps.
- AMSI (Antimalware Scan Interface)
- A Windows interface that lets antivirus scan script content at runtime, including PowerShell; attackers try to disable it in-process.
- Download cradle
- A short PowerShell snippet that fetches code from a remote URL and runs it in memory, without writing a file to disk.
- Encoded command (-EncodedCommand)
- A PowerShell parameter that takes a Base64 string of UTF-16LE command text, used to pass scripts that survive quoting — and to obscure intent.
- Execution policy bypass
- Flags such as -ExecutionPolicy Bypass that turn off PowerShell's script-running safety check — a near-ubiquitous marker in malicious launchers.
- Invoke-Expression (IEX)
- A PowerShell cmdlet that runs a string as code — the execution half of most download cradles and obfuscation chains.
- PowerShell downgrade attack
- Launching PowerShell version 2 to escape the script block logging and AMSI that only exist in version 5.
- Module Logging (4103)
- PowerShell pipeline execution logging: event ID 4103 records commands and bound parameters as they run.
- Windows PowerShell classic log
- The original Windows PowerShell.evtx log holding engine and provider lifecycle (400/403/600) and pipeline execution (800) events.
- Event ID 4104
- The PowerShell Script Block Logging event: one block of compiled code, identified by ScriptBlockId and numbered MessageNumber of MessageTotal.
- Script Block Logging
- A PowerShell 5 feature that records the source of every script block the engine compiles, after de-obfuscation, to event ID 4104.