PowerShell Event ID 40962: Console ready for input
PowerShell console is ready for user inputPowerShell event 40962 follows 40961 when the PowerShell host is ready for input — another default-logged marker of PowerShell use.
40962
- Event ID
- 40962
- Channel
- Microsoft-Windows-PowerShell/Operational
- Provider
- Microsoft-Windows-PowerShell
- Log file
- Microsoft-Windows-PowerShell%4Operational.evtx
- Category
- PowerShell
- Default logging
- Logged by default
What event 40962 means
Event 40962 is written when a PowerShell host has finished starting and is ready to accept commands. It normally follows 40961 within a second or two.
Its main value is the pairing: a 40961/40962 pair means a PowerShell host fully started. Non-interactive hosts running a single command may still produce it, so it is not proof of a human at the keyboard.
When it is logged
Audit policy / configuration
None — the Microsoft-Windows-PowerShell/Operational channel is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| Message | Ready message; use the System section (ProcessID, UserID) for context. |
Common benign sources
- Every PowerShell console launch.
What attackers do that produces it
- Same as 40961 — PowerShell activity on a host or account that does not normally use it.
Investigation tips
- Pair with 40961 by ProcessID and time; pivot to process creation and 400 for command lines.
- Count launches per user and host per day; a sudden rise on a host that rarely runs PowerShell is worth a look.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1059.001 Command and Scripting Interpreter: PowerShell | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.