logo

PowerShell Logging for the Blue Team

ID: 0eadba4d-02ce-5283-bf06-9902fea268d5

STIX ID: report--0eadba4d-02ce-5283-bf06-9902fea268d5

Feed Name: Black Hills Infosec Blog

Date Published: 2016-12-12

Date Updated: 2026-04-27

Author: BHIS

...
...

This report explains how to improve detection of malicious PowerShell activity by upgrading to Windows Management Framework/PowerShell 5.0 and enabling logging features: module logging (Event ID 4103), script block logging (Event ID 4104, with 4105/4106 optional), and full transcription. It covers installing the Administrative Templates for Group Policy, where the PowerShell Operational logs appear, practical considerations (e.g., WMF and .NET dependencies on Windows 7), and recommends enabling script block logging and centralizing logs to support hunting and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.