PowerShell Event ID 800: Pipeline execution details
- Event ID
- 800
- Channel
- Windows PowerShell
- Provider
- PowerShell
- Log file
- Windows PowerShell.evtx
- Category
- PowerShell
- Default logging
- Needs configuration
What event 800 means
Event 800 is the classic-log counterpart of Operational 4103: when module logging is enabled, it records the commands executed in a pipeline and their parameter bindings, along with the host context.
Because it lands in a different log file than 4103, it can survive when the Operational log has been cleared or has rolled over, and it is one more place to recover the exact arguments used by a script.
When it is logged
Turn on Module Logging (Administrative Templates > Windows Components > Windows PowerShell), listing the modules to log (* for all).
Key fields
| Field | What it tells you |
|---|---|
| HostApplication | Command line of the hosting process. |
| CommandLine | The pipeline command line that was executed. |
| Details | CommandInvocation and ParameterBinding lines with the actual parameter values. |
Common benign sources
- Administrative and management scripts once module logging is on.
What attackers do that produces it
- Cmdlet invocations with revealing arguments (download URLs, exclusion paths, remote hosts).
Investigation tips
- Search Details for URLs, IPs,
-ExclusionPath,-ComputerNameand credential parameters. - Compare with 4103 in the Operational log to find gaps where one log was cleared.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1059.001 Command and Scripting Interpreter: PowerShell | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.