Skip to content

Series

PowerShell logging fundamentals

3 posts in this series. Read them in order or jump to any one.

  1. PowerShell Script Block Logging (4104): A Forensics Guide

    What event ID 4104 records, how Windows splits long script blocks across events, why warning-level blocks appear without full logging, and how to read it in a case.

  2. PowerShell Event Logs for Forensics: Every ID That Matters

    A map of PowerShell's forensic event IDs across the Operational and classic Windows PowerShell logs — 4104, 4103, 400, 403, 600, 800 — and what each one proves.

  3. How to Collect PowerShell Logs, Transcripts and History

    Acquire the PowerShell event logs, PSReadLine history and transcripts from a live host, a triage collection or a disk image — with copy-paste commands and the gotchas.

All posts in this series

What event ID 4104 records, how Windows splits long script blocks across events, why warning-level blocks appear without full logging, and how to read it in a case.
A map of PowerShell's forensic event IDs across the Operational and classic Windows PowerShell logs — 4104, 4103, 400, 403, 600, 800 — and what each one proves.
Acquire the PowerShell event logs, PSReadLine history and transcripts from a live host, a triage collection or a disk image — with copy-paste commands and the gotchas.