PowerShell Event ID 4103: Module logging
- Event ID
- 4103
- Channel
- Microsoft-Windows-PowerShell/Operational
- Provider
- Microsoft-Windows-PowerShell
- Log file
- Microsoft-Windows-PowerShell%4Operational.evtx
- Category
- PowerShell
- Default logging
- Needs configuration
What event 4103 means
Event 4103 comes from PowerShell module logging. Instead of the script source (that is 4104), it records what was executed in the pipeline: each command, the values bound to its parameters, and context about the host process and user.
That makes it complementary to 4104. Obfuscated scripts that are hard to read as source often become clear here, because the actual cmdlet calls and their resolved arguments are logged. It is also noisier: every command in every pipeline is recorded for the configured modules.
When it is logged
Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell > Turn on Module Logging, with the module names to log (use * for all modules).
Key fields
| Field | What it tells you |
|---|---|
| ContextInfo | Execution context: host name and version, host application (the command line of the PowerShell process), engine version, runspace ID, user, and the command being run. |
| Payload | The invocation details, e.g. CommandInvocation(Invoke-WebRequest): "Invoke-WebRequest" followed by ParameterBinding(...) lines with each parameter value. |
| UserData | Additional user data, usually empty. |
Common benign sources
- Administrative scripts and management tools running cmdlets.
- Very high volume from monitoring or configuration agents once module logging covers all modules.
What attackers do that produces it
- Parameter values that expose attacker intent — download URLs, file paths, credentials passed as arguments.
- Cmdlets such as
Invoke-WebRequest,Start-BitsTransfer,Add-MpPreference -ExclusionPathwith their real arguments.
Investigation tips
- Read the HostApplication line in ContextInfo to find the PowerShell command line that started the session.
- Search Payload for ParameterBinding values containing URLs, IPs or suspicious paths.
- Pair with 4104 for the same time range to see the source that produced these invocations.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1059.001 Command and Scripting Interpreter: PowerShell | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
33 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 1
- High · 17
- Medium · 10
- Low · 4
- Info · 1
- CriticalBad Opsec Powershell Code ArtifactsRule by ok @securonix invrep_de, oscd.community, SigmaHQ, DRL 1.1
- HighHackTool - Evil-WinRm Execution - PowerShell ModuleRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation CLIP+ Launcher - PowerShell ModuleRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Obfuscated IEX Invocation - PowerShell ModuleRule by Daniel Bohannon (@Mandiant/@FireEye), oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation STDIN+ Launcher - PowerShell ModuleRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR+ Launcher - PowerShell ModuleRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell ModuleRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Stdin - PowerShell ModuleRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Clip - PowerShell ModuleRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use MSHTA - PowerShell ModuleRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Rundll32 - PowerShell ModuleRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighMalicious PowerShell Commandlets - PoshModuleRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighMalicious PowerShell Scripts - PoshModuleRule by frack113, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ModuleRule by Nasreddine Bencherchali (Nextron Systems), frack113, SigmaHQ, DRL 1.1
- HighRemote PowerShell Session (PS Module)Rule by Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, SigmaHQ, DRL 1.1
- HighSuspicious Get-ADDBAccount UsageRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious PowerShell Invocations - Generic - PowerShell ModuleRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious PowerShell Invocations - Specific - PowerShell ModuleRule by Florian Roth (Nextron Systems), Jonhnathan Ribeiro, SigmaHQ, DRL 1.1
- MediumAlternate PowerShell Hosts - PowerShell ModuleRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumClear PowerShell History - PowerShell ModuleRule by Ilyas Ochkov, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, SigmaHQ, DRL 1.1
- MediumInvoke-Obfuscation COMPRESS OBFUSCATION - PowerShell ModuleRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- MediumInvoke-Obfuscation RUNDLL LAUNCHER - PowerShell ModuleRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- MediumPotential Active Directory Enumeration Using AD Module - PsModuleRule by Nasreddine Bencherchali (Nextron Systems), frack113, SigmaHQ, DRL 1.1
- MediumPowerShell Get ClipboardRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumSuspicious Computer Machine Password by PowerShellRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.