Series
Investigating with PowerShell logs
4 posts in this series. Read them in order or jump to any one.
- Decoding PowerShell -EncodedCommand and Obfuscation
How -EncodedCommand and common PowerShell obfuscation work — base64/UTF-16LE, gzip/deflate, char codes, concatenation, the format operator and backticks — and how to decode them safely.
- PSReadLine ConsoleHost_history.txt Forensics
What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.
- PowerShell Transcription Forensics: Reading the Transcript
How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.
- How to Analyze PowerShell Logs in Your Browser
Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.