Skip to content
PowerShell Operational

PowerShell Event ID 40961: Console starting

PowerShell console is starting upPowerShell event 40961 is logged when a PowerShell host starts, giving a timestamp for each PowerShell launch even without script logging.
40961
Event ID
40961
Channel
Microsoft-Windows-PowerShell/Operational
Provider
Microsoft-Windows-PowerShell
Log file
Microsoft-Windows-PowerShell%4Operational.evtx
Category
PowerShell
Default logging
Logged by default

What event 40961 means

Event 40961 is written by the PowerShell Operational log when a PowerShell console or host starts, and 40962 follows when it is ready for input. They carry little data, but they are logged by default, so they show when PowerShell ran even on systems with no script block or module logging.

In an investigation they are timestamps to pivot from: process creation logs, prefetch and the classic Windows PowerShell log (400) fill in who ran it and with which command line.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-PowerShell/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
MessageStartup message; the record has little else (user and process come from the event's System section: Security UserID and Execution ProcessID).

Common benign sources

  • Every interactive PowerShell window and many management agents launching PowerShell.

What attackers do that produces it

  • PowerShell started on hosts or by users that never use it — a lead even when content logging is off.

Investigation tips

  • Use the event's ProcessID and time to find the matching process creation (4688 / Sysmon 1) and its command line.
  • Check the classic Windows PowerShell log 400 at the same time for HostApplication and EngineVersion.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading