Skip to content

Series

Investigating with PowerShell logs

4 posts in this series. Read them in order or jump to any one.

  1. Decoding PowerShell -EncodedCommand and Obfuscation

    How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.

  2. PSReadLine ConsoleHost_history.txt Forensics

    What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.

  3. PowerShell Transcription Forensics: Reading the Transcript

    How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.

  4. How to Analyze PowerShell Logs in Your Browser

    Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.

All posts in this series

How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.
What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.
How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.
Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.