Skip to content
Windows PowerShell

PowerShell Event ID 400: Engine started

Engine state is changed from None to AvailableWindows PowerShell event 400 logs every engine start with HostApplication (the command line) and EngineVersion — key to spot PowerShell v2 downgrades.
400
Event ID
400
Channel
Windows PowerShell
Provider
PowerShell
Log file
Windows PowerShell.evtx
Category
PowerShell
Default logging
Logged by default

What event 400 means

Event 400 is written to the classic Windows PowerShell log each time a PowerShell engine starts in a process — a console, powershell.exe -c, a script host, or an application that hosts PowerShell. It is logged by default, with no policy needed.

Its event data contains key=value lines, of which two matter most. HostApplication is the command line of the hosting process, including -EncodedCommand payloads. EngineVersion is the PowerShell version that ran: a value of 2.0 on a system with PowerShell 5 installed is a downgrade — the version 2 engine does not support script block logging or AMSI, which is exactly why attackers request it with -Version 2.

Event 403 is logged when the same engine stops.

When it is logged

Audit policy / configuration

None — the Windows PowerShell classic event log is enabled by default.

The data is stored as unnamed values; the host details appear as Name=Value lines inside the event data (HostName, HostVersion, HostApplication, EngineVersion, RunspaceId…).

Key fields

FieldWhat it tells you
NewEngineStateState after the change — Available for event 400.
PreviousEngineStateState before the change — None for event 400.
HostApplicationCommand line of the process hosting PowerShell (for example powershell.exe -nop -w hidden -enc ...).
EngineVersionVersion of the PowerShell engine; 2.0 indicates a downgrade when newer versions are installed.
HostNameHost type, e.g. ConsoleHost for powershell.exe, or a custom host name for applications embedding PowerShell.
RunspaceIdRunspace GUID; matches the corresponding 403.

Common benign sources

  • Every PowerShell launch by administrators, installers and management agents.
  • Applications that embed PowerShell (custom HostName values).

What attackers do that produces it

  • Encoded or hidden commands visible in HostApplication — -enc, -w hidden, -nop, IEX download cradles.
  • PowerShell downgrade to version 2 (EngineVersion 2.0) to evade script block logging and AMSI.
  • PowerShell hosted inside unusual processes (unmanaged PowerShell), visible as unexpected HostApplication paths.

Investigation tips

  • Extract HostApplication from all 400 events and decode any Base64 -EncodedCommand arguments.
  • Alert on EngineVersion 2.0 wherever PowerShell 5 is installed.
  • Pair with 403 by RunspaceId for session duration and with 4104 for script content when available.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution
T1689 Downgrade AttackDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

9 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 3
  • Low · 4

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading