Skip to content
Windows PowerShell

PowerShell Event ID 600: Provider started

Provider is StartedWindows PowerShell event 600 is logged as each provider (Registry, FileSystem, Variable…) starts in a new session, repeating HostApplication.
600
Event ID
600
Channel
Windows PowerShell
Provider
PowerShell
Log file
Windows PowerShell.evtx
Category
PowerShell
Default logging
Logged by default

What event 600 means

Event 600 is written several times at the start of each PowerShell session, once per provider loaded: Registry, Alias, Environment, FileSystem, Function, Variable and others. Each record repeats the host details, including HostApplication.

The provider name itself is rarely interesting, but because six or so 600 events accompany every launch, they are a resilient source for the PowerShell command line when 400 events are missing.

When it is logged

Audit policy / configuration

None — the Windows PowerShell classic event log is enabled by default.

Key fields

FieldWhat it tells you
ProviderNameProvider that started (Registry, FileSystem, Variable…).
NewProviderStateStarted.
HostApplicationCommand line of the hosting process.

Common benign sources

  • Every PowerShell launch.

What attackers do that produces it

  • Same as 400 — the command line of encoded or hidden PowerShell launches.

Investigation tips

  • Collect HostApplication values from 600 when 400 is not available, and decode encoded commands.
  • Group the 600 events of one launch by time to count distinct PowerShell sessions.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading