PowerShell Event ID 400: Engine started
- Event ID
- 400
- Channel
- Windows PowerShell
- Provider
- PowerShell
- Log file
- Windows PowerShell.evtx
- Category
- PowerShell
- Default logging
- Logged by default
What event 400 means
Event 400 is written to the classic Windows PowerShell log each time a PowerShell engine starts in a process — a console, powershell.exe -c, a script host, or an application that hosts PowerShell. It is logged by default, with no policy needed.
Its event data contains key=value lines, of which two matter most. HostApplication is the command line of the hosting process, including -EncodedCommand payloads. EngineVersion is the PowerShell version that ran: a value of 2.0 on a system with PowerShell 5 installed is a downgrade — the version 2 engine does not support script block logging or AMSI, which is exactly why attackers request it with -Version 2.
Event 403 is logged when the same engine stops.
When it is logged
None — the Windows PowerShell classic event log is enabled by default.
The data is stored as unnamed values; the host details appear as Name=Value lines inside the event data (HostName, HostVersion, HostApplication, EngineVersion, RunspaceId…).
Key fields
| Field | What it tells you |
|---|---|
| NewEngineState | State after the change — Available for event 400. |
| PreviousEngineState | State before the change — None for event 400. |
| HostApplication | Command line of the process hosting PowerShell (for example powershell.exe -nop -w hidden -enc ...). |
| EngineVersion | Version of the PowerShell engine; 2.0 indicates a downgrade when newer versions are installed. |
| HostName | Host type, e.g. ConsoleHost for powershell.exe, or a custom host name for applications embedding PowerShell. |
| RunspaceId | Runspace GUID; matches the corresponding 403. |
Common benign sources
- Every PowerShell launch by administrators, installers and management agents.
- Applications that embed PowerShell (custom HostName values).
What attackers do that produces it
- Encoded or hidden commands visible in HostApplication —
-enc,-w hidden,-nop,IEXdownload cradles. - PowerShell downgrade to version 2 (EngineVersion
2.0) to evade script block logging and AMSI. - PowerShell hosted inside unusual processes (unmanaged PowerShell), visible as unexpected HostApplication paths.
Investigation tips
- Extract HostApplication from all 400 events and decode any Base64
-EncodedCommandarguments. - Alert on EngineVersion 2.0 wherever PowerShell 5 is installed.
- Pair with 403 by RunspaceId for session duration and with 4104 for script content when available.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
9 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 3
- Low · 4
- HighDelete Volume Shadow Copies Via WMI With PowerShellRule by frack113, SigmaHQ, DRL 1.1
- HighPowerShell Called from an Executable Version MismatchRule by Sean Metcalf (source), Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumNetcat The Powershell VersionRule by frack113, SigmaHQ, DRL 1.1
- MediumNslookup PowerShell Download CradleRule by Sai Prashanth Pulisetti @pulisettis, Aishwarya Singam, SigmaHQ, DRL 1.1
- MediumPowerShell Downgrade Attack - PowerShellRule by Florian Roth (Nextron Systems), Lee Holmes (idea), Harish Segar (improvements), SigmaHQ, DRL 1.1
- LowPowerShell Download Via Net.WebClient - PowerShell ClassicRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- LowRemote PowerShell Session (PS Classic)Rule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- LowRenamed Powershell Under Powershell ChannelRule by Harish Segar, frack113, SigmaHQ, DRL 1.1
- LowUse Get-NetTCPConnectionRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.