PowerShell Event ID 4105: Script block invocation started
- Event ID
- 4105
- Channel
- Microsoft-Windows-PowerShell/Operational
- Provider
- Microsoft-Windows-PowerShell
- Log file
- Microsoft-Windows-PowerShell%4Operational.evtx
- Category
- PowerShell
- Default logging
- Needs configuration
What event 4105 means
Event 4105 is written when a script block starts executing, and 4106 when it finishes. They carry the ScriptBlockId of the block logged in 4104, so they tell you when — and how often — a given piece of code actually ran, not just that it was compiled.
These events are only produced when invocation logging is turned on in the Script Block Logging policy, and they are very noisy. Most environments leave them off; when present, they help order activity precisely.
When it is logged
Turn on PowerShell Script Block Logging with the option "Log script block invocation start / stop events" enabled.
Key fields
| Field | What it tells you |
|---|---|
| ScriptBlockId | GUID of the script block; matches the 4104 that logged its text. |
| RunspaceId | Runspace (PowerShell session) in which the block ran. |
Common benign sources
- Any PowerShell activity when invocation logging is enabled — mostly noise.
What attackers do that produces it
- Confirms repeated execution of a malicious block (for example a loop or scheduled re-run).
Investigation tips
- Join to 4104 on ScriptBlockId to get the code, then use 4105/4106 times for duration.
- Group by RunspaceId to separate concurrent sessions.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1059.001 Command and Scripting Interpreter: PowerShell | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.