Glossary
Script Block Logging
A PowerShell 5 feature that records the source of every script block the engine compiles, after de-obfuscation, to event ID 4104.
Script Block Logging is a PowerShell 5.0 feature that writes the text of each script block the engine compiles to event ID 4104 in the Microsoft-Windows-PowerShell/Operational log. Because logging happens after the code is de-obfuscated, an -EncodedCommand or a concatenated one-liner is recorded in its expanded form (Microsoft).
It is enabled by Group Policy or the registry value EnableScriptBlockLogging. Even when disabled, PowerShell logs blocks containing suspicious terms at the Warning level. Long blocks are split across several 4104 events sharing a ScriptBlockId. See the 4104 forensics guide.