Skip to content
PowerShell Operational

PowerShell Event ID 4104: Script block logging

Creating Scriptblock textPowerShell event 4104 logs the text of executed script blocks, after decoding — the richest record of what PowerShell actually ran.
4104
Event ID
4104
Channel
Microsoft-Windows-PowerShell/Operational
Provider
Microsoft-Windows-PowerShell
Log file
Microsoft-Windows-PowerShell%4Operational.evtx
Category
PowerShell
Default logging
Needs configuration

What event 4104 means

Event 4104 is written by the PowerShell engine when it compiles a script block. The ScriptBlockText field holds the code as PowerShell sees it: commands typed at the prompt, whole scripts, functions, and — crucially — code that was Base64-encoded, downloaded or built at run time, because logging happens after that layer is removed.

Large scripts are split across several events that share a ScriptBlockId; MessageNumber and MessageTotal tell you how to reassemble them. The Path field is filled when the block came from a script file.

Even without any policy, PowerShell 5 and later log script blocks that contain known-suspicious keywords at the Warning level. Full logging of every block requires the Script Block Logging policy, which is what makes 4104 the backbone of PowerShell investigations.

When it is logged

Audit policy / configuration

Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging (or registry HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging = 1).

Without the policy, Windows PowerShell 5.x still logs blocks it considers suspicious as Warning-level 4104 events. PowerShell 7 writes to the PowerShellCore/Operational channel and has its own policy settings.

Key fields

FieldWhat it tells you
ScriptBlockTextThe code of the script block, after de-obfuscation layers such as -EncodedCommand have been removed.
ScriptBlockIdGUID shared by all parts of one script block; group by it to reassemble long scripts.
MessageNumberPart number of this event for a split script block.
MessageTotalTotal number of parts for the script block.
PathScript file the block came from; empty for interactive or in-memory code.

Common benign sources

  • Administrative scripts, configuration management (SCCM, Intune, DSC) and monitoring agents.
  • PowerShell's own modules and profile scripts loading at startup.
  • Software installers and IT automation that use PowerShell under the hood.

What attackers do that produces it

  • Download cradles such as IEX (New-Object Net.WebClient).DownloadString(...) and Invoke-WebRequest pulling payloads.
  • Encoded or obfuscated commands, recovered here in readable form.
  • Offensive frameworks and tools loaded in memory (credential dumping, AD reconnaissance, AMSI bypass attempts).
  • Defense tampering commands such as Set-MpPreference -DisableRealtimeMonitoring.

Investigation tips

  • Filter Level 3 (Warning) first — those are the blocks PowerShell itself flagged as suspicious.
  • Reassemble split blocks by ScriptBlockId in MessageNumber order before reading.
  • Search ScriptBlockText for network indicators (URLs, IPs), FromBase64String, Invoke-Expression, -bxor, Reflection.Assembly and AMSI-related strings.
  • Find the process that ran the block with Sysmon 1 / Security 4688 (powershell.exe command line) and the classic log's 400 event (HostApplication).

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution
T1027.010 Obfuscated Files or Information: Command ObfuscationStealth
T1140 Deobfuscate/Decode Files or InformationStealth
T1105 Ingress Tool TransferCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

162 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 2
  • High · 51
  • Medium · 89
  • Low · 20

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4104: PowerShell Script Block Logging explained

Sources and further reading