PowerShell Event ID 4104: Script block logging
- Event ID
- 4104
- Channel
- Microsoft-Windows-PowerShell/Operational
- Provider
- Microsoft-Windows-PowerShell
- Log file
- Microsoft-Windows-PowerShell%4Operational.evtx
- Category
- PowerShell
- Default logging
- Needs configuration
What event 4104 means
Event 4104 is written by the PowerShell engine when it compiles a script block. The ScriptBlockText field holds the code as PowerShell sees it: commands typed at the prompt, whole scripts, functions, and — crucially — code that was Base64-encoded, downloaded or built at run time, because logging happens after that layer is removed.
Large scripts are split across several events that share a ScriptBlockId; MessageNumber and MessageTotal tell you how to reassemble them. The Path field is filled when the block came from a script file.
Even without any policy, PowerShell 5 and later log script blocks that contain known-suspicious keywords at the Warning level. Full logging of every block requires the Script Block Logging policy, which is what makes 4104 the backbone of PowerShell investigations.
When it is logged
Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging (or registry HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging = 1).
Without the policy, Windows PowerShell 5.x still logs blocks it considers suspicious as Warning-level 4104 events. PowerShell 7 writes to the PowerShellCore/Operational channel and has its own policy settings.
Key fields
| Field | What it tells you |
|---|---|
| ScriptBlockText | The code of the script block, after de-obfuscation layers such as -EncodedCommand have been removed. |
| ScriptBlockId | GUID shared by all parts of one script block; group by it to reassemble long scripts. |
| MessageNumber | Part number of this event for a split script block. |
| MessageTotal | Total number of parts for the script block. |
| Path | Script file the block came from; empty for interactive or in-memory code. |
Common benign sources
- Administrative scripts, configuration management (SCCM, Intune, DSC) and monitoring agents.
- PowerShell's own modules and profile scripts loading at startup.
- Software installers and IT automation that use PowerShell under the hood.
What attackers do that produces it
- Download cradles such as
IEX (New-Object Net.WebClient).DownloadString(...)andInvoke-WebRequestpulling payloads. - Encoded or obfuscated commands, recovered here in readable form.
- Offensive frameworks and tools loaded in memory (credential dumping, AD reconnaissance, AMSI bypass attempts).
- Defense tampering commands such as
Set-MpPreference -DisableRealtimeMonitoring.
Investigation tips
- Filter Level 3 (Warning) first — those are the blocks PowerShell itself flagged as suspicious.
- Reassemble split blocks by ScriptBlockId in MessageNumber order before reading.
- Search ScriptBlockText for network indicators (URLs, IPs),
FromBase64String,Invoke-Expression,-bxor,Reflection.Assemblyand AMSI-related strings. - Find the process that ran the block with Sysmon 1 / Security 4688 (powershell.exe command line) and the classic log's 400 event (HostApplication).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
162 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 2
- High · 51
- Medium · 89
- Low · 20
- CriticalSilence.EDA DetectionRule by Alina Stepchenkova, Group-IB, oscd.community, SigmaHQ, DRL 1.1
- CriticalSuspicious PowerShell Mailbox Export to Share - PSRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighAADInternals PowerShell Cmdlets Execution - PsScriptRule by Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighAbuse of Service Permissions to Hide Services Via Set-Service - PSRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighAMSI Bypass Pattern Assembly GetTypeRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighClearing Windows Console HistoryRule by Austin Songer @austinsonger, SigmaHQ, DRL 1.1
- HighCode Executed Via Office Add-in XLL FileRule by frack113, SigmaHQ, DRL 1.1
- HighCreate Volume Shadow Copy with PowershellRule by frack113, SigmaHQ, DRL 1.1
- HighDeletion of Volume Shadow Copies via WMI with PowerShell - PS ScriptRule by Tim Rauch, frack113, SigmaHQ, DRL 1.1
- HighDisable of ETW Trace - PowershellRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighDisable Powershell Command HistoryRule by Ali Alwashali, SigmaHQ, DRL 1.1
- HighDisable-WindowsOptionalFeature Command PowerShellRule by frack113, SigmaHQ, DRL 1.1
- HighDSInternals Suspicious PowerShell Cmdlets - ScriptBlockRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - Rubeus Execution - ScriptBlockRule by Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - WinPwn Execution - ScriptBlockRule by Swachchhanda Shrawan Poudel, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation CLIP+ Launcher - PowerShellRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Obfuscated IEX Invocation - PowerShellRule by Daniel Bohannon (@Mandiant/@FireEye), oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation STDIN+ Launcher - PowershellRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR+ Launcher - PowerShellRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShellRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Stdin - PowershellRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Clip - PowershellRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use MSHTA - PowerShellRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Rundll32 - PowerShellRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighLive Memory Dump Using PowershellRule by Max Altgelt (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.