Skip to content
Windows PowerShell

PowerShell Event ID 800: Pipeline execution details

Pipeline execution detailsWindows PowerShell event 800 records pipeline execution details (commands and parameters) when module logging is enabled.
800
Event ID
800
Channel
Windows PowerShell
Provider
PowerShell
Log file
Windows PowerShell.evtx
Category
PowerShell
Default logging
Needs configuration

What event 800 means

Event 800 is the classic-log counterpart of Operational 4103: when module logging is enabled, it records the commands executed in a pipeline and their parameter bindings, along with the host context.

Because it lands in a different log file than 4103, it can survive when the Operational log has been cleared or has rolled over, and it is one more place to recover the exact arguments used by a script.

When it is logged

Audit policy / configuration

Turn on Module Logging (Administrative Templates > Windows Components > Windows PowerShell), listing the modules to log (* for all).

Key fields

FieldWhat it tells you
HostApplicationCommand line of the hosting process.
CommandLineThe pipeline command line that was executed.
DetailsCommandInvocation and ParameterBinding lines with the actual parameter values.

Common benign sources

  • Administrative and management scripts once module logging is on.

What attackers do that produces it

  • Cmdlet invocations with revealing arguments (download URLs, exclusion paths, remote hosts).

Investigation tips

  • Search Details for URLs, IPs, -ExclusionPath, -ComputerName and credential parameters.
  • Compare with 4103 in the Operational log to find gaps where one log was cleared.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading