Glossary
Windows PowerShell classic log
The original Windows PowerShell.evtx log holding engine and provider lifecycle (400/403/600) and pipeline execution (800) events.
The Windows PowerShell log (Windows PowerShell.evtx) is PowerShell's original event log, present and enabled by default on every version. It records engine lifecycle — 400 (engine Available/start), 403 (engine stopped) — provider lifecycle 600, and pipeline execution 800.
Its detail blocks are Key=Value lines carrying HostName, HostApplication (the full command line, often the most telling field), EngineVersion and RunspaceId. Because it is on by default, it is frequently the only PowerShell evidence on hosts without script block logging. See the event-log guide.