Skip to content

Glossary

PowerShell transcription

A feature that writes a full text record of a PowerShell session — input and output — to a PowerShell_transcript file, with local timestamps.

PowerShell transcription records the input and output of a session to a text file, started by Start-Transcript or forced by the "Turn on PowerShell Transcription" policy. Files are named PowerShell_transcript.<computer>.<random>.<timestamp>.txt, saved to the user's Documents folder or a policy OutputDirectory.

The header records the start time, username, machine, host application, process ID and PowerShell version. With -IncludeInvocationHeader, each command carries a Command start time. All times are the host's local clock, with no zone. See transcription forensics.