Skip to content
PowerShell Operational

PowerShell Event ID 4106: Script block invocation completed

Completed invocation of ScriptBlockPowerShell event 4106 marks the end of a script block's execution, paired with 4105 by ScriptBlockId when invocation logging is enabled.
4106
Event ID
4106
Channel
Microsoft-Windows-PowerShell/Operational
Provider
Microsoft-Windows-PowerShell
Log file
Microsoft-Windows-PowerShell%4Operational.evtx
Category
PowerShell
Default logging
Needs configuration

What event 4106 means

Event 4106 closes the pair opened by 4105: the script block identified by ScriptBlockId finished executing. The gap between the two events is the block's run time.

Like 4105 it only exists when invocation logging is enabled, and it is mainly useful for precise ordering of script execution in a timeline.

When it is logged

Audit policy / configuration

Turn on PowerShell Script Block Logging with the option "Log script block invocation start / stop events" enabled.

Key fields

FieldWhat it tells you
ScriptBlockIdGUID of the script block; matches 4104 and 4105.
RunspaceIdRunspace in which the block ran.

Common benign sources

  • Any PowerShell execution when invocation logging is on.

What attackers do that produces it

  • A 4105 without a 4106 can mean the block was still running (for example a long-lived implant loop) when logging stopped.

Investigation tips

  • Pair with 4105 to compute duration; look for long-running blocks.
  • Get the code from 4104 with the same ScriptBlockId.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading