Microsoft-Windows-PowerShell
189 events across 3 channels
Event ID 4097 — Computer Name $null or.
Message
Event ID 4098 — Resolving to default scheme http
Message
Event ID 4099 — Remote shell name resolved to default Microsoft.
Message
Event ID 4100 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
ContextInfo | Context |
UserData | — |
Payload | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 4100
version: 1
level: 3
task: 106
opcode: 19
keywords: 0
time_created: '2022-04-07T17:04:47.579256+00:00'
event_record_id: 144
correlation:
ActivityID: E0AAB88C-4A9F-0000-0BCA-AAE09F4AD801
execution:
process_id: 380
thread_id: 3624
channel: Microsoft-Windows-PowerShell/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ContextInfo: " Severity = Warning\r\n Host Name = ADMUX\r\n Host
Version = 1.0.0.0\r\n Host ID = 2e800f71-2f5c-4821-bd98-9e3b61b6b054\r\n
\ Host Application = C:\\Windows\\system32\\dsac.exe\r\n Engine Version
= 5.1.20348.617\r\n Runspace ID = 4e800c4b-dc8b-408d-8e82-38150ba7d4fe\r\n
\ Pipeline ID = 31\r\n Command Name = Set-ADAccountPassword\r\n Command
Type = Cmdlet\r\n Script Name = \r\n Command Path = \r\n Sequence
Number = 23\r\n User = SIGMA\\Administrator\r\n Connected User =
\r\n Shell ID = Microsoft.PowerShell\r\n"
UserData: ''
Payload: "Error Message = The password does not meet the length, complexity, or
history requirement of the domain.\r\nFully Qualified Error ID = ActiveDirectoryServer:1325,Microsoft.ActiveDirectory.Management.Commands.SetADAccountPassword\r\n"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4101 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
Context | — |
User_Data | — |
ContextInfo | — |
UserData | — |
Payload | — |
Event ID 4102 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
ContextInfo | Context |
UserData | — |
Payload | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 4102
version: 1
level: 3
task: 106
opcode: 19
keywords: 0
time_created: '2023-10-25T21:34:05.630892+00:00'
event_record_id: 11
correlation:
ActivityID: DE03B784-07C3-0001-BC98-04DEC307DA01
execution:
process_id: 1796
thread_id: 2088
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDevEval
security:
user_id: S-1-5-21-2533829718-189860685-2477588761-500
event_data:
ContextInfo: " Severity = Warning\r\n Host Name = ConsoleHost\r\n
\ Host Version = 5.1.22621.2428\r\n Host ID = d4db7522-7ab1-46f8-add0-ee6f22c6c812\r\n
\ Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe
-ExecutionPolicy Bypass a:\\FixPublicNetworkType.ps1\r\n Engine Version
= 5.1.22621.2428\r\n Runspace ID = c5b2be04-de37-4a47-bfdd-d75d2d714efd\r\n
\ Pipeline ID = 1\r\n Command Name = \r\n Command Type = \r\n
\ Script Name = \r\n Command Path = \r\n Sequence Number =
16\r\n User = WINDEVEVAL\\Administrator\r\n Connected User = \r\n
\ Shell ID = Microsoft.PowerShell\r\n"
UserData: ''
Payload: "Error Message = Could not find the drive 'a:\\'. The drive might not be
ready or might not be mapped.\r\n\r\nProvider name = Microsoft.PowerShell.Core\\FileSystem\r\n"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4103 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
ContextInfo | Context |
UserData | — |
Payload | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 4103
version: 1
level: 4
task: 106
opcode: 20
keywords: 0
time_created: '2023-11-06T01:35:06.007359+00:00'
event_record_id: 907
correlation:
ActivityID: E4DB489E-1037-0000-CD79-E9E43710DA01
execution:
process_id: 15468
thread_id: 15184
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
ContextInfo: " Severity = Informational\r\n Host Name = ConsoleHost\r\n
\ Host Version = 5.1.22621.2428\r\n Host ID = 9500ad9e-7709-413f-b91b-8945cbb52940\r\n
\ Host Application = powershell.exe -NoExit -Command &{Import-Module \"C:\\Program
Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Microsoft.VisualStudio.DevShell.dll\";
Enter-VsDevShell d5dcd421 -SkipAutomaticLocation -DevCmdArguments \"-arch=x64
-host_arch=x64\"}\r\n Engine Version = 5.1.22621.2428\r\n Runspace
ID = 6fa4bb48-d600-4d4b-b445-e1fa0a41db53\r\n Pipeline ID = 23\r\n Command
Name = Set-StrictMode\r\n Command Type = Cmdlet\r\n Script Name
= C:\\Program Files\\WindowsPowerShell\\Modules\\PSReadLine\\2.0.0\\PSReadLine.psm1\r\n
\ Command Path = \r\n Sequence Number = 58\r\n User = WINDEV2310EVAL\\User\r\n
\ Connected User = \r\n Shell ID = Microsoft.PowerShell\r\n"
UserData: ''
Payload: "CommandInvocation(Set-StrictMode): \"Set-StrictMode\"\r\nParameterBinding(Set-StrictMode):
name=\"Off\"; value=\"True\"\r\n"
message: ''
Sigma Rules
- Potential Active Directory Enumeration Using AD Module - PsModule
Detects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration. - Alternate PowerShell Hosts - PowerShell Module
Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe - Bad Opsec Powershell Code Artifacts
focuses on trivial artifacts observed in variants of prevalent offensive ps1 payloads, including Cobalt Strike Beacon, PoshC2, Powerview, Letmein, Empire, Powersploit, and other attack payloads that often undergo minimal changes by attackers due to bad opsec. - Clear PowerShell History - PowerShell Module
Detects keywords that could indicate clearing PowerShell history - PowerShell Decompress Commands
A General detection for specific decompress commands in PowerShell logs. This could be an adversary decompressing files.
Showing 5 of 33 matching Sigma rules.
References
- Microsoft Learn https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4104 — Creating Scriptblock text (%1 of %2): %3 ScriptBlock ID: %4 Path: %5.
Message
Fields
| Name | Description |
|---|---|
MessageNumber | — |
MessageTotal | — |
ScriptBlockText | — |
ScriptBlockId | ScriptBlock ID. |
Path | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 4104
version: 1
level: 5
task: 2
opcode: 15
keywords: 0
time_created: '2023-11-06T01:35:05.990326+00:00'
event_record_id: 901
correlation:
ActivityID: E4DB489E-1037-0002-FA44-ECE43710DA01
execution:
process_id: 15468
thread_id: 15184
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
MessageNumber: 1
MessageTotal: 1
ScriptBlockText: prompt
ScriptBlockId: 6baf0dc7-a83f-43e1-bb6a-d7ab8d05eeb0
Path: ''
message: ''
Sigma Rules
- AADInternals PowerShell Cmdlets Execution - PsScript
Detects ADDInternals Cmdlet execution. A tool for administering Azure AD and Office 365. Which can be abused by threat actors to attack Azure AD or Office 365. - Access to Browser Login Data
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store. - Potential Active Directory Enumeration Using AD Module - PsScript
Detects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration. - Powershell Add Name Resolution Policy Table Rule
Detects powershell scripts that adds a Name Resolution Policy Table (NRPT) rule for the specified namespace. This will bypass the default DNS server and uses a specified server for answering the query. - Add Windows Capability Via PowerShell Script
Detects usage of the "Add-WindowsCapability" cmdlet to add Windows capabilities. Notable capabilities could be "OpenSSH" and others.
Showing 5 of 160 matching Sigma rules.
References
- Microsoft Learn https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4105 — Started invocation of ScriptBlock ID: %1 Runspace ID: %2.
Message
Fields
| Name | Description |
|---|---|
ScriptBlockId | Started invocation of ScriptBlock ID. |
RunspaceId | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 4105
version: 1
level: 5
task: 102
opcode: 15
keywords: 0
time_created: '2023-11-06T01:35:05.999333+00:00'
event_record_id: 906
correlation:
ActivityID: E4DB489E-1037-0000-CC79-E9E43710DA01
execution:
process_id: 15468
thread_id: 15184
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
ScriptBlockId: 4b7eebd5-d6e3-46f7-b795-a7d9736e5810
RunspaceId: 6fa4bb48-d600-4d4b-b445-e1fa0a41db53
message: ''
References
- Microsoft Learn https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4106 — Completed invocation of ScriptBlock ID: %1 Runspace ID: %2.
Message
Fields
| Name | Description |
|---|---|
ScriptBlockId | Completed invocation of ScriptBlock ID. |
RunspaceId | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 4106
version: 1
level: 5
task: 103
opcode: 15
keywords: 0
time_created: '2023-11-06T01:35:05.993908+00:00'
event_record_id: 905
correlation:
ActivityID: E4DB489E-1037-0002-FB44-ECE43710DA01
execution:
process_id: 15468
thread_id: 15184
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
ScriptBlockId: 6baf0dc7-a83f-43e1-bb6a-d7ab8d05eeb0
RunspaceId: 6fa4bb48-d600-4d4b-b445-e1fa0a41db53
message: ''
References
- Microsoft Learn https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7937 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
Context | — |
User_Data | — |
ContextInfo | — |
UserData | — |
Payload | — |
Event ID 7938 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
Context | — |
User_Data | — |
ContextInfo | — |
UserData | — |
Payload | — |
Event ID 7939 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
Context | — |
User_Data | — |
ContextInfo | — |
UserData | — |
Payload | — |
Event ID 7940 — %3 Context: %1 User Data: %2.
Message
Fields
| Name | Description |
|---|---|
Context | — |
User_Data | — |
ContextInfo | — |
UserData | — |
Payload | — |
Event ID 7941 — Correlating activity id's.
Message
Fields
| Name | Description |
|---|---|
CurrentActivityId | — |
ParentActivityId | — |
currentActivityId | — |
parentActivityId | — |
Event ID 7942 — Class Name = %1 Method Name = %2 Workflow GUID = %3 Message = %4 %5 Activity Name = %6 Activity GUID = %7 Parameters = %8.
Message
Fields
| Name | Description |
|---|---|
ClassName | — |
MethodName | — |
WorkflowGuid | — |
Message | — |
JobData | — |
ActivityName | — |
ActivityGuid | — |
Parameters | — |
Event ID 8193 — Creating Runspace object Instance Id.
Message
Fields
| Name | Description |
|---|---|
InstanceId | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 8193
version: 1
level: 5
task: 1
opcode: 16
keywords: 0
time_created: '2022-04-07T17:06:32.284732+00:00'
event_record_id: 9
correlation:
ActivityID: C88130F4-85B6-4F22-BDD1-6F6F4B29582D
execution:
process_id: 5272
thread_id: 5572
channel: Microsoft-Windows-PowerShell/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
param1: c88130f4-85b6-4f22-bdd1-6f6f4b29582d
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8194 — Creating RunspacePool object InstanceId %1 MinRunspaces %2 MaxRunspaces %3.
Message
Fields
| Name | Description |
|---|---|
InstanceId | — |
MaxRunspaces | — |
MinRunspaces | — |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 8194
version: 1
level: 5
task: 1
opcode: 16
keywords: 0
time_created: '2022-04-07T17:21:29.409715+00:00'
event_record_id: 146
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 4780
channel: Microsoft-Windows-PowerShell/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
InstanceId: 1480b89f-e871-42e4-bfb4-c8f88b053137
MaxRunspaces: '2'
MinRunspaces: '10'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8195 — Opening RunspacePool
Message
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 8195
version: 1
level: 5
task: 1
opcode: 10
keywords: 0
time_created: '2022-04-07T17:21:29.483155+00:00'
event_record_id: 147
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 4780
channel: Microsoft-Windows-PowerShell/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8196 — Modifying activity Id and correlating
Message
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 8196
version: 1
level: 4
task: 0
opcode: 20
keywords: 0
time_created: '2022-04-07T17:21:43.024925+00:00'
event_record_id: 191
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 940
channel: Microsoft-Windows-PowerShell/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8197 — Runspace state changed to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 8198 — Attempting session creation retry %1 for error code %2 on session Id %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 12033 — Port resolved to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 12034 — AppName resolved to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 12035 — ComputerName resolved to %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 12036 — Scheme is %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 12037 — Test analytic message
Message
Event ID 12038 — Connection Paramters are Connection URI: %1 Resource URI: %2 User: %3 OpenTimeout: %4 IdleTimeout: %5 CancelTimeout: %6 AuthenticationMechanism: %7...
Message
Fields
| Name | Description |
|---|---|
Connection_URI | — |
Resource_URI | — |
User | — |
OpenTimeout | — |
IdleTimeout | — |
CancelTimeout | — |
AuthenticationMechanism | — |
Thumb_Print | — |
MaxUriRedirectionCount | — |
MaxReceivedDataSizePerCommand | — |
MaxReceivedObjectSize | — |
uri | — |
shell | — |
userName | — |
opentimeout | — |
idletimeout | — |
canceltimeout | — |
auth | — |
thumbPrint | — |
redircount | — |
recvdDataSize | — |
recvdObjSize | — |
Event ID 12039 — Modifying activity Id and correlating
Message
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 12039
version: 1
level: 4
task: 0
opcode: 20
keywords: 0
time_created: '2022-04-07T17:21:43.024926+00:00'
event_record_id: 192
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 940
channel: Microsoft-Windows-PowerShell/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16385 — AmsiUtil state.
Message
Fields
| Name | Description |
|---|---|
state | — |
Context | — |
Action | — |
AmsiContext | — |
Event ID 24577 — Windows PowerShell ISE has started to run script file %1.
Message
Fields
| Name | Description |
|---|---|
FileName | — |
Event ID 24578 — Windows PowerShell ISE has started to run a user-selected script from file %1.
Message
Fields
| Name | Description |
|---|---|
FileName | — |
Event ID 24579 — Windows PowerShell ISE is stopping the current command.
Message
Event ID 24580 — Windows PowerShell ISE is resuming the debugger.
Message
Event ID 24581 — Windows PowerShell ISE is stopping the debugger.
Message
Event ID 24582 — Windows PowerShell ISE is stepping into debugging.
Message
Event ID 24583 — Windows PowerShell ISE is stepping over debugging.
Message
Event ID 24584 — Windows PowerShell ISE is stepping out of debugging.
Message
Event ID 24592 — Windows PowerShell ISE is enabling all breakpoints.
Message
Event ID 24593 — Windows PowerShell ISE is disabling all breakpoints.
Message
Event ID 24594 — Windows PowerShell ISE is removing all breakpoints.
Message
Event ID 24595 — Windows PowerShell ISE is setting the breakpoint at line #: %1 of file %2.
Message
Fields
| Name | Description |
|---|---|
CurrentLine | — |
FileName | — |
Event ID 24596 — Windows PowerShell ISE is removing the breakpoint on line #: %1 of file %2.
Message
Fields
| Name | Description |
|---|---|
CurrentLine | — |
FileName | — |
Event ID 24597 — Windows PowerShell ISE is enabling the breakpoint on line #: %1 of file %2.
Message
Fields
| Name | Description |
|---|---|
CurrentLine | — |
FileName | — |
Event ID 24598 — Windows PowerShell ISE is disabling the breakpoint on line #: %1 of file %2.
Message
Fields
| Name | Description |
|---|---|
CurrentLine | — |
FileName | — |
Event ID 24599 — Windows PowerShell ISE has hit a breakpoint on line #: %1 of file %2.
Message
Fields
| Name | Description |
|---|---|
CurrentLine | — |
FileName | — |
Event ID 28673 — Successfully rehydrated an object.
Message
Fields
| Name | Description |
|---|---|
DeserializedType | — |
CastedToType | — |
RehydratedType | — |
Event ID 28674 — Failed to rehydrated an object.
Message
Fields
| Name | Description |
|---|---|
DeserializedType | — |
CastedToType | — |
TypeCastException | — |
TypeCastInnerException | — |
Event ID 28675 — Serialization depth has been overriden.
Message
Fields
| Name | Description |
|---|---|
Serialized_type_name | — |
Original_depth | — |
Overriden_depth | — |
Current_depth_below_top_level | — |
SerializedType | — |
OriginalDepth | — |
OverridenDepth | — |
CurrentDepthBelowTopLevel | — |
Event ID 28676 — Serialization mode has been overriden.
Message
Fields
| Name | Description |
|---|---|
Serialized_type_name | — |
Overriden_mode | — |
SerializedType | — |
OverridenMode | — |
Event ID 28677 — Serialization of a script property has been skipped, because there is no runspace to use for evaluation of the property.
Message
Fields
| Name | Description |
|---|---|
Property_name | — |
Property_owners_type_name | Property owner's type name. |
Getter_script | — |
PropertyName | — |
PropertyOwnerType | — |
GetterScript | — |
Event ID 28678 — Serialization of a property has been skipped, because property getter failed.
Message
Fields
| Name | Description |
|---|---|
PropertyName | — |
PropertyOwnerType | — |
Exception | — |
InnerException | — |
Event ID 28679 — Serialization of an enumerable object might not be complete, because object being enumerated threw an exception.
Message
Fields
| Name | Description |
|---|---|
TypeBeingEnumerated | — |
Exception | — |
Event ID 28680 — Serialization called object's ToString method which failed.
Message
Fields
| Name | Description |
|---|---|
Type | — |
Exception | — |
Event ID 28682 — Maximum depth below top level has been reached, forcing object to be serialized as strings.
Message
Fields
| Name | Description |
|---|---|
Object_type_at_max_depth | — |
Property_name_at_max_depth | — |
Depth | — |
TypeOfObjectAtMaxDepth | — |
PropertyNameAtMaxDepth | — |
Event ID 28683 — XmlException has been thrown by the deserializer (most likely indicating incorrect clixml format).
Message
Fields
| Name | Description |
|---|---|
Line_number | — |
Line_position | — |
Exception | — |
LineNumber | — |
LinePosition | — |
Event ID 28684 — Serialization of specified properties failed, because one of the specified properties was missing.
Message
Fields
| Name | Description |
|---|---|
TypeOfObjectWithMissingProperty | — |
PropertyName | — |
Event ID 32769 — Received object with Runspace Id: %1 Command Id: %2 Destination: %3 DataType: %4 TargetInterface: %5.
Message
Fields
| Name | Description |
|---|---|
Runspace_InstanceId | — |
PowerShell_InstanceId | — |
Destination | — |
DataType | — |
TargetInterface | — |
Event ID 32775 — An unhandled exception occurred in the appdomain.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 32776 — Runspace Id: %1 Pipeline Id: %2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
PipelineId | — |
ErrorCode | — |
ErrorMessage | — |
StackTrace | — |
Event ID 32777 — An unhandled exception occurred in the appdomain.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 32784 — Runspace Id: %1 Pipeline Id: %2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
PipelineId | — |
ErrorCode | — |
ErrorMessage | — |
StackTrace | — |
Event ID 32785 — Runspace Id %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 32786 — Runspace Id %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 32787 — Runspace Id.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 32788 — Runspace Id.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 32789 — Runspace Id: %1 Pipeline Id: %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
Pipeline_Id | — |
SessionId | — |
PipelineId | — |
DataSize | — |
Event ID 32790 — Runspace Id: %1 Pipeline Id: %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
Pipeline_Id | — |
SessionId | — |
PipelineId | — |
Event ID 32791 — Runspace Id: %1 Pipeline Id: %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
Pipeline_Id | — |
SessionId | — |
PipelineId | — |
Event ID 32792 — Runspace Id: %1 Pipeline Id: %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
Pipeline_Id | — |
SessionId | — |
PipelineId | — |
DataSize | — |
Event ID 32793 — Runspace Id %1 Pipeline Id %2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
PipelineId | — |
Event ID 32800 — Runspace Id %1 Pipeline Id %2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
PipelineId | — |
Event ID 32801 — Runspace Id: %1 Pipeline Id %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
SessionId | — |
PipelineId | — |
Event ID 32802 — Runspace Id: %1 Pipeline Id %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
SessionId | — |
PipelineId | — |
Event ID 32803 — Runspace Id: %1 Pipeline Id %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
SessionId | — |
PipelineId | — |
SignalCode | — |
Event ID 32804 — Runspace Id: %1 Pipeline Id %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
SessionId | — |
PipelineId | — |
Event ID 32805 — Runspace Id.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Uri | — |
Event ID 32849 — Runspace Id: %1 Pipeline Id: %2.
Message
Fields
| Name | Description |
|---|---|
Runspace_Id | — |
Pipeline_Id | — |
TargetInterface | 3 to client. DataType. |
Runspace_InstanceId | — |
PowerShell_InstanceId | — |
DataSize | — |
DataType | — |
Event ID 32850 — Request %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 32851 — Reporting context for request: %1 Context Reported: %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 32852 — Reporting operation complete for request: %1 Error Code: %2 Error Message: %3 StackTrace: %4.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 32853 — Shell Context %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 32854 — Shell Context %1 Command Context %2 Request Id %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 32855 — Shell Context %1 Command Context %2 Request Id %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 32856 — Shell Context %1 Command Context %2 Request Id %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 32857 — Shell Context %1 Command Context %2 IsReceiveOperation %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 32865 — Loading assembly %1 for custom shell with shell Id %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 32866 — Loading type %1 for custom shell with shell Id %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 32867 — Received remoting fragment.
Message
Fields
| Name | Description |
|---|---|
Object_Id | — |
Fragment_Id | — |
Start_Flag | — |
End_Flag | — |
Payload_Length | — |
Payload_Data | — |
ObjectId | — |
FragmentId | — |
sFlag | — |
eFlag | — |
FragmentLength | — |
FragmentPayload | — |
Event ID 32868 — Sent remoting fragment.
Message
Fields
| Name | Description |
|---|---|
Object_Id | — |
Fragment_Id | — |
Start_Flag | — |
End_Flag | — |
Payload_Length | — |
Payload_Data | — |
ObjectId | — |
FragmentId | — |
sFlag | — |
eFlag | — |
FragmentLength | — |
FragmentPayload | — |
Event ID 32869 — Shutting down winrm service.
Message
Event ID 40961 — PowerShell console is starting up
Message
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 40961
version: 1
level: 4
task: 4
opcode: 1
keywords: 0
time_created: '2023-11-06T01:18:27.730646+00:00'
event_record_id: 772
correlation:
ActivityID: E4DB489E-1037-0002-CA26-E6E43710DA01
execution:
process_id: 12192
thread_id: 16872
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 40962 — PowerShell console is ready for user input
Message
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 40962
version: 1
level: 4
task: 4
opcode: 2
keywords: 0
time_created: '2023-11-06T01:18:31.505927+00:00'
event_record_id: 788
correlation:
ActivityID: E4DB489E-1037-0002-CA26-E6E43710DA01
execution:
process_id: 12192
thread_id: 16872
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 45057 — Tracing ErrorRecord: Message: %1 CategoryInfo.
Message
Fields
| Name | Description |
|---|---|
Message | [Tracing ErrorRecord] Message. |
CategoryInfoCategory | [Tracing ErrorRecord] CategoryInfo.Category. |
CategoryInfoReason | [Tracing ErrorRecord] CategoryInfo.Reason. |
CategoryInfoTargetName | [Tracing ErrorRecord] CategoryInfo.TargetName. |
FullyQualifiedErrorId | [Tracing ErrorRecord] FullyQualifiedErrorId. |
Message | [Exception Details] Message. |
Stack_Trace | [Exception Details] Stack Trace. |
Category | — |
Reason | — |
TargetName | — |
ExceptionMessage | — |
ExceptionStackTrace | — |
ExceptionInnerException | — |
Event ID 45058 — Exception: Message: %1 StackTrace: %2 InnerException : %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 45059 — Tracing PSObject
Message
Event ID 45060 — Tracing Job: Id: %1 InstanceId: %2 Name: %3 Location: %4 State: %5 Command: %6.
Message
Fields
| Name | Description |
|---|---|
Id | [Tracing Job] Id. |
InstanceId | [Tracing Job] InstanceId. |
Name | [Tracing Job] Name. |
Location | [Tracing Job] Location. |
State | [Tracing Job] State. |
Command | [Tracing Job] Command. |
Event ID 45061 — Trace Information.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 45062 — Connection Paramters are Connection URI: %1 Resource URI: %2 User: %3 OpenTimeout: %4 IdleTimeout: %5 CancelTimeout: %6 AuthenticationMechanism: %7...
Message
Fields
| Name | Description |
|---|---|
Connection_URI | — |
Resource_URI | — |
User | — |
OpenTimeout | — |
IdleTimeout | — |
CancelTimeout | — |
AuthenticationMechanism | — |
Thumb_Print | — |
MaxUriRedirectionCount | — |
MaxReceivedDataSizePerCommand | — |
MaxReceivedObjectSize | — |
uri | — |
shell | — |
userName | — |
opentimeout | — |
idletimeout | — |
canceltimeout | — |
auth | — |
thumbPrint | — |
redircount | — |
recvdDataSize | — |
recvdObjSize | — |
Event ID 45063 — Workflow plugin loaded.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
User | — |
HostingMode | — |
Protocol | — |
Configuration | — |
endpointName | — |
user | — |
hostingMode | — |
protocol | — |
configuration | — |
Event ID 45064 — Workflow execution started.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ManagedNodes | — |
workflowId | — |
managedNodes | — |
Event ID 45065 — Workflow state changed.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
NewState | — |
OldState | — |
workflowId | — |
newState | — |
oldState | — |
Event ID 45072 — Workflow plugin has been requested for a shutdown.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
endpointName | — |
Event ID 45073 — Workflow plugin restarted.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
endpointName | — |
Event ID 45074 — Workflow is resuming.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45075 — A quota limit that was set for the endpoint was exceeded.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
ConfigName | — |
AllowedValue | — |
ValueInQuestion | — |
endpointName | — |
configName | — |
allowedValue | — |
valueInQuestion | — |
Event ID 45076 — Workflow has resumed.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45078 — Workflow runspace pool was created.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ManagedNode | — |
workflowId | — |
managedNode | — |
Event ID 45079 — Activity was queued for execution.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ActivityName | — |
workflowId | — |
activityName | — |
Event ID 45080 — Activity execution started.
Message
Fields
| Name | Description |
|---|---|
ActivityName | — |
ActivityTypeName | — |
activityName | — |
activityTypeName | — |
Event ID 45081 — Workflow is being imported from a XAML file.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
XamlFile | — |
workflowId | — |
xamlFile | — |
Event ID 45082 — Workflow has been imported from a XAML file.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
XamlFile | — |
workflowId | — |
xamlFile | — |
Event ID 45083 — Workflow could not be imported from a XAML file because of an error.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ErrorDescription | — |
workflowId | — |
errorDescription | — |
Event ID 45084 — Workflow validation started.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45085 — Workflow validation succeeded.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45086 — Workflow validation failed with error.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45087 — Workflow activity validated.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ActivityDisplayName | — |
ActivityTypeName | — |
workflowId | — |
activityDisplayName | — |
activityType | — |
Event ID 45088 — Workflow activity could not be validated.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ActivityDisplayName | — |
ActivityTypeName | — |
workflowId | — |
activityDisplayName | — |
activityType | — |
Event ID 45089 — Activity execution failed.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ActivityName | — |
FailureDescription | — |
workflowId | — |
activityName | — |
failureDescription | — |
Event ID 45090 — Runspace availability changed.
Message
Fields
| Name | Description |
|---|---|
RunspaceId | — |
Availability | — |
runspaceId | — |
availability | — |
Event ID 45091 — Runspace state changed.
Message
Fields
| Name | Description |
|---|---|
RunspaceId | — |
NewState | — |
OldState | — |
runspaceId | — |
newState | — |
oldState | — |
Event ID 45092 — Workflow loaded for execution.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45093 — Workflow unloaded.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45094 — Workflow execution cancelled.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45095 — Workflow execution aborted.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45096 — Workflow cleanup operation executed.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45097 — Persisted workflow loaded from disk.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
Path | — |
workflowId | — |
path | — |
Event ID 45098 — Workflow data was deleted from disk.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
Path | — |
workflowId | — |
path | — |
Event ID 45100 — Starting remove job.
Message
Fields
| Name | Description |
|---|---|
JobId | — |
jobId | — |
Event ID 45101 — Job state changed.
Message
Fields
| Name | Description |
|---|---|
JobId | — |
WorkflowId | — |
NewState | — |
OldState | — |
jobId | — |
workflowId | — |
newState | — |
oldState | — |
Event ID 45102 — Job error.
Message
Fields
| Name | Description |
|---|---|
JobId | — |
WorkflowId | — |
ErrorDescription | — |
jobId | — |
workflowId | — |
errorDescription | — |
Event ID 45104 — Job created for workflow (child job).
Message
Fields
| Name | Description |
|---|---|
ParentJobId | — |
ChildJobId | — |
ChildWorkflowId | — |
parentJobId | — |
childJobId | — |
childWorkflowId | — |
Event ID 45105 — Parent job created for workflow.
Message
Fields
| Name | Description |
|---|---|
JobId | — |
jobId | — |
Event ID 45106 — All required jobs were created for workflow execution.
Message
Fields
| Name | Description |
|---|---|
JobId | — |
WorkflowId | — |
jobId | — |
workflowId | — |
Event ID 45107 — Child job removed for workflow.
Message
Fields
| Name | Description |
|---|---|
ParentJobId | — |
ChildJobId | — |
WorkflowId | — |
parentJobId | — |
childJobId | — |
workflowId | — |
Event ID 45108 — An error occurred while removing job.
Message
Fields
| Name | Description |
|---|---|
ParentJobId | — |
ChildJobId | — |
WorkflowId | — |
Error | — |
parentJobId | — |
childJobId | — |
workflowId | — |
error | — |
Event ID 45109 — Loading workflow for execution.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45110 — Workflow execution finished.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45111 — Cancelling workflow execution.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45112 — Aborting workflow execution.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
Reason | — |
workflowId | — |
reason | — |
Event ID 45113 — Unloading workflow.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45114 — Forced workflow shutdown started.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45115 — Forced workflow shutdown finished.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45116 — An error occurred while forcefully shutting down a workflow.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ErrorDescription | — |
workflowId | — |
errorDescription | — |
Event ID 45117 — Persisting workflow to disk.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
PersistPath | — |
workflowId | — |
persistPath | — |
Event ID 45118 — Workflow persisted to disk.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
workflowId | — |
Event ID 45119 — Activity execution finished.
Message
Fields
| Name | Description |
|---|---|
ActivityName | — |
activityName | — |
Event ID 45120 — Workflow execution error.
Message
Fields
| Name | Description |
|---|---|
WorkflowId | — |
ErrorDescription | — |
workflowId | — |
errorDescription | — |
Event ID 45121 — A new PowerShell endpoint was registered.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
EndpointType | — |
RegisteredBy | — |
endpointName | — |
endpointType | — |
registeredBy | — |
Event ID 45122 — Endpoint configuration modified.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
ModifiedBy | — |
endpointName | — |
modifiedBy | — |
Event ID 45123 — Endpoint configuration unregistered.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
UnregisteredBy | — |
endpointName | — |
unregisteredBy | — |
Event ID 45124 — Endpoint configuration disabled.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
DisabledBy | — |
endpointName | — |
disabledBy | — |
Event ID 45125 — Endpoint configuration enabled.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
EnabledBy | — |
endpointName | — |
enabledBy | — |
Event ID 45126 — Out of process runspace started.
Message
Fields
| Name | Description |
|---|---|
Command | — |
command | — |
Event ID 45127 — Parameter splatting was performed during workflow execution.
Message
Fields
| Name | Description |
|---|---|
Parameters | — |
Computers | — |
parameters | — |
computers | — |
Event ID 45128 — Workflow engine started.
Message
Fields
| Name | Description |
|---|---|
EndpointName | — |
endpointName | — |
Event ID 45129 — Workflow manager instantiated with CheckpointPath: %1 ConfigProviderId: %2 UserName: %3 Path: %4.
Message
Fields
| Name | Description |
|---|---|
CheckpointPath | — |
ConfigProviderId | — |
UserName | — |
Path | — |
checkpointPath | — |
configProviderId | — |
userName | — |
path | — |
Event ID 46337 — BEGIN ImportWorkflowCommand::StartWorkflowApplication.
Message
Fields
| Name | Description |
|---|---|
TrackingId | — |
Event ID 46338 — END ImportWorkflowCommand::StartWorkflowApplication.
Message
Fields
| Name | Description |
|---|---|
TrackingId | — |
Event ID 46339 — BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication.
Message
Fields
| Name | Description |
|---|---|
TrackingId | — |
Event ID 46340 — END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.
Message
Fields
| Name | Description |
|---|---|
TrackingId | — |
Event ID 46341 — END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.
Message
Fields
| Name | Description |
|---|---|
TrackingId | — |
ContainerParentJobInstanceId | — |
Event ID 46342 — BEGIN JobLogic ContainerParentJob Guid %1.
Message
Fields
| Name | Description |
|---|---|
WorkflowJobJobInstanceId | — |
Event ID 46343 — END JobLogic ContainerParentJob Guid %1.
Message
Fields
| Name | Description |
|---|---|
WorkflowJobJobInstanceId | — |
Event ID 46344 — BEGIN WorkflowExecution ContainerParentJob Guid %1.
Message
Fields
| Name | Description |
|---|---|
WorkflowJobJobInstanceId | — |
Event ID 46345 — END WorkflowExecution ContainerParentJob Guid %1.
Message
Fields
| Name | Description |
|---|---|
WorkflowJobJobInstanceId | — |
Event ID 46346 — WorkflowJob with Guid %1 added to ContainerParentJob with Guid %2.
Message
Fields
| Name | Description |
|---|---|
WorkflowJobInstanceId | — |
ContainerParentJobInstanceId | — |
Event ID 46347 — ProxyJob with Guid %1 associated with remote ContainerParentJob with Guid %2.
Message
Fields
| Name | Description |
|---|---|
ProxyJobInstanceId | — |
ContainerParentJobInstanceId | — |
Event ID 46348 — BEGIN Execution of ContainerParentJob with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ContainerParentJobInstanceId | — |
Event ID 46349 — END Execution of ContainerParentJob with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ContainerParentJobInstanceId | — |
Event ID 46350 — BEGIN Execution of Proxy Job with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ProxyJobInstanceId | — |
Event ID 46351 — END Execution of Proxy Job with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ProxyJobInstanceId | — |
Event ID 46352 — BEGIN StateChanged event handler for Proxy Job with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ProxyJobInstanceId | — |
Event ID 46353 — END StateChanged event handler for Proxy Job with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ProxyJobInstanceId | — |
Event ID 46354 — BEGIN StateChanged event handler for Proxy Child Job with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ProxyChildJobInstanceId | — |
Event ID 46355 — END StateChanged event handler for Proxy Child Job with Guid %1.
Message
Fields
| Name | Description |
|---|---|
ProxyChildJobInstanceId | — |
Event ID 46356 — BEGIN Running garbage collection
Message
Event ID 46357 — END Running garbage collection
Message
Event ID 46358 — Persistence store has reached its maximum specified size
Message
Event ID 49152 —
Message
Fields
| Name | Description |
|---|---|
message | — |
Event ID 49153 — Trace Information: %1 %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 53249 — Scheduled Job %1 started at %2.
Message
Fields
| Name | Description |
|---|---|
ScheduledJobDefName | — |
StartTime | — |
Event ID 53250 — Scheduled Job %1 completed at %2 with state %3.
Message
Fields
| Name | Description |
|---|---|
ScheduledJobDefName | — |
StopTime | — |
State | — |
Event ID 53251 — Scheduled Job Exception %1: Message: %2 StackTrace: %3 InnerException: %4.
Message
Fields
| Name | Description |
|---|---|
Message | — |
StackTrace | — |
InnerException | — |
Name | — |
Event ID 53504 — Windows PowerShell has started an IPC listening thread on process: %1 in AppDomain: %2.
Message
Fields
| Name | Description |
|---|---|
param1 | Windows PowerShell has started an IPC listening thread on process. |
param2 | in AppDomain. |
Example Event
system:
provider: Microsoft-Windows-PowerShell
guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
event_source_name: ''
event_id: 53504
version: 1
level: 4
task: 111
opcode: 10
keywords: 0
time_created: '2023-11-06T01:18:29.006927+00:00'
event_record_id: 774
correlation:
ActivityID: E4DB489E-1037-0002-CA26-E6E43710DA01
execution:
process_id: 12192
thread_id: 10468
channel: Microsoft-Windows-PowerShell/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
param1: '12192'
param2: DefaultAppDomain
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 53505 — Windows PowerShell has ended an IPC listening thread on process: %1 in AppDomain: %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 53506 — An error has occurred in Windows PowerShell IPC listening thread on process: %1 in AppDomain: %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53507 — Windows PowerShell IPC connect on process: %1 in AppDomain: %2 for User: %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53508 — Windows PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |