Skip to content
PowerShell Operational

PowerShell Event ID 4103: Module logging

Executing PipelinePowerShell event 4103 (module logging) records pipeline execution: each command invoked, with its parameter bindings and the host context.
4103
Event ID
4103
Channel
Microsoft-Windows-PowerShell/Operational
Provider
Microsoft-Windows-PowerShell
Log file
Microsoft-Windows-PowerShell%4Operational.evtx
Category
PowerShell
Default logging
Needs configuration

What event 4103 means

Event 4103 comes from PowerShell module logging. Instead of the script source (that is 4104), it records what was executed in the pipeline: each command, the values bound to its parameters, and context about the host process and user.

That makes it complementary to 4104. Obfuscated scripts that are hard to read as source often become clear here, because the actual cmdlet calls and their resolved arguments are logged. It is also noisier: every command in every pipeline is recorded for the configured modules.

When it is logged

Audit policy / configuration

Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell > Turn on Module Logging, with the module names to log (use * for all modules).

Key fields

FieldWhat it tells you
ContextInfoExecution context: host name and version, host application (the command line of the PowerShell process), engine version, runspace ID, user, and the command being run.
PayloadThe invocation details, e.g. CommandInvocation(Invoke-WebRequest): "Invoke-WebRequest" followed by ParameterBinding(...) lines with each parameter value.
UserDataAdditional user data, usually empty.

Common benign sources

  • Administrative scripts and management tools running cmdlets.
  • Very high volume from monitoring or configuration agents once module logging covers all modules.

What attackers do that produces it

  • Parameter values that expose attacker intent — download URLs, file paths, credentials passed as arguments.
  • Cmdlets such as Invoke-WebRequest, Start-BitsTransfer, Add-MpPreference -ExclusionPath with their real arguments.

Investigation tips

  • Read the HostApplication line in ContextInfo to find the PowerShell command line that started the session.
  • Search Payload for ParameterBinding values containing URLs, IPs or suspicious paths.
  • Pair with 4104 for the same time range to see the source that produced these invocations.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

33 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 1
  • High · 17
  • Medium · 10
  • Low · 4
  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading