Skip to content
PowerShell Operational

PowerShell Event ID 4105: Script block invocation started

Started invocation of ScriptBlockPowerShell event 4105 marks the start of a script block's execution; with 4106 it gives run times for blocks logged by 4104.
4105
Event ID
4105
Channel
Microsoft-Windows-PowerShell/Operational
Provider
Microsoft-Windows-PowerShell
Log file
Microsoft-Windows-PowerShell%4Operational.evtx
Category
PowerShell
Default logging
Needs configuration

What event 4105 means

Event 4105 is written when a script block starts executing, and 4106 when it finishes. They carry the ScriptBlockId of the block logged in 4104, so they tell you when — and how often — a given piece of code actually ran, not just that it was compiled.

These events are only produced when invocation logging is turned on in the Script Block Logging policy, and they are very noisy. Most environments leave them off; when present, they help order activity precisely.

When it is logged

Audit policy / configuration

Turn on PowerShell Script Block Logging with the option "Log script block invocation start / stop events" enabled.

Key fields

FieldWhat it tells you
ScriptBlockIdGUID of the script block; matches the 4104 that logged its text.
RunspaceIdRunspace (PowerShell session) in which the block ran.

Common benign sources

  • Any PowerShell activity when invocation logging is enabled — mostly noise.

What attackers do that produces it

  • Confirms repeated execution of a malicious block (for example a loop or scheduled re-run).

Investigation tips

  • Join to 4104 on ScriptBlockId to get the code, then use 4105/4106 times for duration.
  • Group by RunspaceId to separate concurrent sessions.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading