Skip to content

4104script blocksPSReadLinetranscripts

PowerShell Parser

Reassemble Script Block Logging (event 4104) from the .evtx, read the classic PowerShell log, PSReadLine history and transcripts, and decode encoded commands and obfuscation — all in your browser with WebAssembly. Nothing is uploaded.

Drop PowerShell logs, history and transcripts here

Microsoft-Windows-PowerShell%4Operational.evtx and Windows PowerShell.evtx, ConsoleHost_history.txt and PowerShell_transcript.*.txt. Folders and ZIP triage collections (KAPE, Velociraptor) work as-is.

A synthetic set from a fictional intrusion — no real data. Tip: open the flagged 4104 event and use the de-obfuscation view below.

100% client-side: files are parsed by WebAssembly in your browser and never uploaded. Nothing is ever executed.

How to get your data

Full acquisition guide

Export the PowerShell event logs and copy PSReadLine history and transcripts from every account, then drop the result here. On a live Windows host this takes about two minutes.

  1. Export the logs and copy history / transcripts
  2. Drop the folder or ZIP here
  3. Parsed in your browser, never uploaded

Paste into Windows PowerShell run as administrator (system drive C:). It exports the operational and classic PowerShell logs (and PowerShell 7's log if present), then copies every account's PSReadLine history and transcripts, keeping the Users\<name>\ path so each is attributed.

PowerShell · Admin
New-Item -ItemType Directory -Force C:\triage\logs | Out-Null
wevtutil epl Microsoft-Windows-PowerShell/Operational "C:\triage\logs\Microsoft-Windows-PowerShell%4Operational.evtx" /ow:true
wevtutil epl "Windows PowerShell" "C:\triage\logs\Windows PowerShell.evtx" /ow:true
wevtutil epl PowerShellCore/Operational "C:\triage\logs\PowerShellCore%4Operational.evtx" /ow:true 2>$null
robocopy C:\Users C:\triage\Users *_history.txt PowerShell_transcript.*.txt /S /XJ /R:0 /W:0 /NP /NDL

Result: C:\triage\logs\*.evtx plus C:\triage\Users\<user>\… with the history and transcript files. Drop the whole C:\triage folder here (drag it, or use Choose a folder).

Analysing on another machine? Pack it into one ZIP with the tar.exe built into Windows 10 1803 and later:

PowerShell / cmd
tar -a -c -f C:\triage\powershell.zip -C C:\triage logs Users

Gotchas

  • Script Block Logging (4104) is off by default until enabled by policy; even then, Windows still logs blocks it considers suspicious at Warning level. The classic Windows PowerShell log and PSReadLine history are on by default.
  • The EventLog service keeps logs open, so a plain file copy fails. Use wevtutil epl, KAPE or Velociraptor.
  • PSReadLine history has no timestamps and can be weeks older than the logs; treat its order as the only chronology and corroborate with the event logs.
  • Transcripts record the host's local wall-clock time with no zone: note the machine's time zone when you correlate with UTC event logs.

De-obfuscation view

Paste any command line, -EncodedCommand string or obfuscated blob. It is decoded layer by layer (base64/UTF-16LE, gzip/deflate, char codes, concatenation, format operator, backticks) and shown as inert text — nothing is executed.

What PowerShell logs record

PowerShell writes several independent trails. Script Block Logging (event 4104, in the Microsoft-Windows-PowerShell/Operational log) records the actual code that ran — the deobfuscated script text, split across several 4104 events for long blocks. Module logging (4103) records pipeline execution details. The classic "Windows PowerShell" log records engine and provider lifecycle (400/403/600) and, with a policy, pipeline execution (800).

Outside the event logs, PSReadLine keeps a plain-text history of everything typed at an interactive console, and Start-Transcript (or the transcription policy) writes a full transcript of a session to a text file. Together they are one of the richest records of what an operator — or an intruder — did on a Windows host.

Where it is stored

  • C:\Windows\System32\winevt\Logs\Microsoft-Windows-PowerShell%4Operational.evtx — Script Block Logging (4104) and module logging (4103).
  • C:\Windows\System32\winevt\Logs\Windows PowerShell.evtx — classic engine/provider/pipeline events (400/403/600/800).
  • C:\Users\<user>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt — interactive command history, per user.
  • C:\Users\<user>\Documents\PowerShell_transcript.<host>.<random>.<timestamp>.txt — transcripts, when enabled.

Why it matters in an investigation

  • Script Block Logging captures the code as PowerShell saw it, so an -EncodedCommand or an obfuscated one-liner is recorded in its expanded form — this parser also decodes the encoded and compressed layers for you.
  • The reassembly of 4104 by ScriptBlockId and MessageNumber/MessageTotal rebuilds long scripts that Windows split across many events, and flags any missing part.
  • PSReadLine history and transcripts capture interactive activity that may never touch a script file, including typos and abandoned commands.
  • Findings point out download cradles, AMSI/ETW bypasses, logging and Defender tampering, execution-policy bypass, hidden windows, engine downgrades and common obfuscation — as leads to verify, not verdicts.

Limitations

  • Script Block Logging is off by default; without it you may only see Warning-level blocks Windows flagged on its own, plus the classic log and history.
  • PSReadLine history has no timestamps: its order is the only chronology, and it can be far older than the logs.
  • Transcript times are the host's local clock with no zone; event-log times are UTC.
  • Logs roll over and can be cleared; this tool flags clearing commands but cannot recover events already removed.

How to get the files

  • Export the two PowerShell event logs with wevtutil epl (or collect every .evtx with KAPE / Velociraptor), and copy each user's PSReadLine history and transcripts.
  • The EventLog service keeps logs open on a live host, so use an export rather than a plain copy.
  • Keep the Users\<name>\ folder structure so history and transcripts are attributed to the right account.

FAQ

Are my files uploaded anywhere?

No. The parser — including the .evtx reader — is Rust compiled to WebAssembly and runs in a Web Worker in your browser. There is no upload endpoint, and nothing in a script is ever executed.

Does it decode -EncodedCommand and obfuscated scripts?

Yes. Base64 -EncodedCommand is decoded from UTF-16LE, and further layers — gzip/deflate payloads, [char] codes, string concatenation, the -f format operator and backtick escaping — are unwound and shown as inert text. It never runs the script.

How does it rebuild a script block that spans several events?

Windows splits a long script block across several 4104 events sharing a ScriptBlockId, each carrying MessageNumber of MessageTotal. The parser groups by ScriptBlockId, orders by MessageNumber, concatenates the text and flags any missing part.

What if Script Block Logging was turned off?

You will still see the classic Windows PowerShell log (engine and pipeline events), PSReadLine history and any transcripts. Windows also logs script blocks it considers suspicious at Warning level even when full logging is off, and those are captured too.

Which files should I collect?

Microsoft-Windows-PowerShell%4Operational.evtx and Windows PowerShell.evtx from winevt\Logs, each user's ConsoleHost_history.txt, and any PowerShell_transcript.*.txt. The built-in collection guide gives one-command exports.

Step-by-step: open PowerShell .evtx logs, PSReadLine history and transcripts in a free in-browser viewer, reassemble script blocks, decode encoded commands and export CSV or JSON.
How PowerShell transcripts are structured, what the header records, how command timestamps work with -IncludeInvocationHeader, and how to investigate them.
What the PSReadLine history file records, where it lives, why it has no timestamps, and how to use it — and its limits — in an investigation.