← Event ID reference
4104

PowerShell script block logged

  • Log: Microsoft-Windows-PowerShell/Operational
  • Source: Microsoft-Windows-PowerShell
  • Tampering & persistence
  • Info

What it means

With script block logging enabled, records the PowerShell code that ran (in Microsoft-Windows-PowerShell/Operational).

Why it matters

Reveals obfuscated or encoded PowerShell used by attackers.

What to do

  • Enable "Turn on PowerShell Script Block Logging" by Group Policy.
  • Flag scripts using EncodedCommand, DownloadString or Invoke-Expression.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Microsoft-Windows-PowerShell/Operational'; Id = 4104
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us