PowerShell Event ID 600: Provider started
- Event ID
- 600
- Channel
- Windows PowerShell
- Provider
- PowerShell
- Log file
- Windows PowerShell.evtx
- Category
- PowerShell
- Default logging
- Logged by default
What event 600 means
Event 600 is written several times at the start of each PowerShell session, once per provider loaded: Registry, Alias, Environment, FileSystem, Function, Variable and others. Each record repeats the host details, including HostApplication.
The provider name itself is rarely interesting, but because six or so 600 events accompany every launch, they are a resilient source for the PowerShell command line when 400 events are missing.
When it is logged
None — the Windows PowerShell classic event log is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| ProviderName | Provider that started (Registry, FileSystem, Variable…). |
| NewProviderState | Started. |
| HostApplication | Command line of the hosting process. |
Common benign sources
- Every PowerShell launch.
What attackers do that produces it
- Same as 400 — the command line of encoded or hidden PowerShell launches.
Investigation tips
- Collect HostApplication values from 600 when 400 is not available, and decode encoded commands.
- Group the 600 events of one launch by time to count distinct PowerShell sessions.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1059.001 Command and Scripting Interpreter: PowerShell | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighTamper Windows Defender - PSClassicRule by frack113, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.