Skip to content
Windows PowerShell

PowerShell Event ID 403: Engine stopped

Engine state is changed from Available to StoppedWindows PowerShell event 403 logs when a PowerShell engine stops; paired with 400 it bounds a PowerShell session in time.
403
Event ID
403
Channel
Windows PowerShell
Provider
PowerShell
Log file
Windows PowerShell.evtx
Category
PowerShell
Default logging
Logged by default

What event 403 means

Event 403 is the counterpart of 400: the PowerShell engine in a process moved from Available to Stopped. It repeats the host details, including HostApplication and EngineVersion, so it is useful even when the matching 400 has rolled out of the log.

The time between 400 and 403 for the same runspace is how long that PowerShell session lived — seconds for a one-shot command, hours for an interactive or implant session.

When it is logged

Audit policy / configuration

None — the Windows PowerShell classic event log is enabled by default.

Key fields

FieldWhat it tells you
NewEngineStateStopped.
PreviousEngineStateAvailable.
HostApplicationCommand line of the hosting process.
EngineVersionEngine version that ran.
RunspaceIdRunspace GUID, matching the 400.

Common benign sources

  • Every PowerShell session ending.

What attackers do that produces it

  • Very long-lived PowerShell sessions started with hidden windows can indicate an implant or C2 loop.

Investigation tips

  • Pair with 400 by RunspaceId to compute session duration.
  • Use HostApplication here when the 400 is gone.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading