4104
PowerShell script block logged
- Log: Microsoft-Windows-PowerShell/Operational
- Source: Microsoft-Windows-PowerShell
- Tampering & persistence
- Info
What it means
With script block logging enabled, records the PowerShell code that ran (in Microsoft-Windows-PowerShell/Operational).
Why it matters
Reveals obfuscated or encoded PowerShell used by attackers.
What to do
- Enable "Turn on PowerShell Script Block Logging" by Group Policy.
- Flag scripts using EncodedCommand, DownloadString or Invoke-Expression.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Microsoft-Windows-PowerShell/Operational'; Id = 4104
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us