Microsoft-Windows-PowerShell

EventTitleChannelSampleRule
4097Computer Name $null or.OperationalNN
4098Resolving to default scheme httpOperationalNN
4099Remote shell name resolved to default Microsoft.OperationalNN
4100Payload Context: ContextInfo User Data: UserData.OperationalYN
4101Payload Context: ContextInfo User Data: UserData.OperationalYN
4102Payload Context: ContextInfo User Data: UserData.OperationalYN
4103Payload Context: ContextInfo User Data: UserData.OperationalYY
4104Creating Scriptblock text (MessageNumber of MessageTotal).OperationalYY
4105Started invocation of ScriptBlock ID: ScriptBlockId.OperationalYN
4106Completed invocation of ScriptBlock ID: ScriptBlockId.OperationalYN
7937ContextInfo Context: Context User Data: User_Data.AnalyticYN
7938Payload Context: ContextInfo User Data: UserData.AnalyticYN
7939Payload Context: ContextInfo User Data: UserData.AnalyticYN
7940ContextInfo Context: Context User Data: User_Data.AnalyticNN
7941Correlating activity id's.AnalyticNN
7942Class Name = ClassName.AnalyticYN
8193Creating Runspace object Instance Id.OperationalYN
8194Creating RunspacePool object.OperationalYN
8195Opening RunspacePoolOperationalYN
8196Modifying activity Id and correlatingOperationalYN
8197Runspace state changed to param1.OperationalYN
8198Attempting session creation retry param1 for error code param2 on session Id …OperationalNN
12033Port resolved to param1.AnalyticNN
12034AppName resolved to param1.AnalyticNN
12035ComputerName resolved to param1.AnalyticYN
12036Scheme is param1.AnalyticNN
12037Test analytic messageAnalyticNN
12038Connection Paramters are Connection URI: Connection_URI Resource URI: …AnalyticNN
12039Modifying activity Id and correlatingOperationalYN
16385AmsiUtil state.AnalyticYN
24577Windows PowerShell ISE has started to run script file FileName.OperationalNN
24578Windows PowerShell ISE has started to run a user-selected script from file …OperationalNN
24579Windows PowerShell ISE is stopping the current command.OperationalNN
24580Windows PowerShell ISE is resuming the debugger.OperationalNN
24581Windows PowerShell ISE is stopping the debugger.OperationalNN
24582Windows PowerShell ISE is stepping into debugging.OperationalNN
24583Windows PowerShell ISE is stepping over debugging.OperationalNN
24584Windows PowerShell ISE is stepping out of debugging.OperationalNN
24592Windows PowerShell ISE is enabling all breakpoints.OperationalNN
24593Windows PowerShell ISE is disabling all breakpoints.OperationalNN
24594Windows PowerShell ISE is removing all breakpoints.OperationalNN
24595Windows PowerShell ISE is setting the breakpoint at line #: CurrentLine of file …OperationalNN
24596Windows PowerShell ISE is removing the breakpoint on line #: CurrentLine of file …OperationalNN
24597Windows PowerShell ISE is enabling the breakpoint on line #: CurrentLine of file …OperationalNN
24598Windows PowerShell ISE is disabling the breakpoint on line #: CurrentLine of …OperationalNN
24599Windows PowerShell ISE has hit a breakpoint on line #: CurrentLine of file …OperationalNN
28673Successfully rehydrated an object.AnalyticYN
28674Failed to rehydrated an object.AnalyticNN
28675Serialization depth has been overriden.AnalyticNN
28676Serialization mode has been overriden.AnalyticNN
28677Serialization of a script property has been skipped, because there is no …AnalyticNN
28678Serialization of a property has been skipped, because property getter failed.AnalyticNN
28679Serialization of an enumerable object might not be complete, because object …AnalyticNN
28680Serialization called object's ToString method which failed.AnalyticNN
28682Maximum depth below top level has been reached, forcing object to be serialized …AnalyticNN
28683XmlException has been thrown by the deserializer (most likely indicating …AnalyticNN
28684Serialization of specified properties failed, because one of the specified …AnalyticNN
32769Received object with Runspace Id: Runspace_InstanceId Command Id: …AnalyticYN
32775An unhandled exception occurred in the appdomain.AnalyticNN
32776Runspace Id: SessionId Pipeline Id: PipelineId.AnalyticYN
32777An unhandled exception occurred in the appdomain.OperationalNN
32784Runspace Id: SessionId Pipeline Id: PipelineId.OperationalYN
32785Runspace Id param1.AnalyticYN
32786Runspace Id param1.AnalyticYN
32787Runspace Id: RunspaceId.AnalyticYN
32788Runspace Id: RunspaceId.AnalyticYN
32789Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.AnalyticYN
32790Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.AnalyticYN
32791Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.AnalyticNN
32792Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.AnalyticYN
32793Runspace Id SessionId Pipeline Id PipelineId.AnalyticYN
32800Runspace Id SessionId Pipeline Id PipelineId.AnalyticYN
32801Runspace Id: Runspace_Id Pipeline Id SessionId.AnalyticYN
32802Runspace Id: Runspace_Id Pipeline Id SessionId.AnalyticYN
32803Runspace Id: Runspace_Id Pipeline Id SessionId.AnalyticNN
32804Runspace Id: Runspace_Id Pipeline Id SessionId.AnalyticNN
32805Runspace Id: SessionId.AnalyticNN
32849Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.AnalyticYN
32850Request param1.AnalyticNN
32851Reporting context for request: ReportingContextForRequest Context Reported: …AnalyticYN
32852Reporting operation complete for request: ReportingOperationCompleteForRequest.AnalyticYN
32853Shell Context param1.AnalyticYN
32854Shell Context param1 Command Context param2 Request Id param3.AnalyticNN
32855Shell Context param1 Command Context param2 Request Id param3.AnalyticYN
32856Shell Context param1 Command Context param2 Request Id param3.AnalyticYN
32857Shell Context param1 Command Context param2 IsReceiveOperation param3.AnalyticNN
32865Loading assembly param1 for custom shell with shell Id param2.AnalyticNN
32866Loading type param1 for custom shell with shell Id param2.AnalyticNN
32867Received remoting fragment.AnalyticYN
32868Sent remoting fragment.AnalyticYN
32869Shutting down winrm service.AnalyticNN
40961PowerShell console is starting upOperationalYN
40962PowerShell console is ready for user inputOperationalYN
45057Tracing ErrorRecord.DebugNN
45058Exception: Message: Message StackTrace: StackTrace InnerException : …DebugNN
45059Tracing PSObjectDebugNN
45060Tracing Job: Id: Id InstanceId: InstanceId Name: Name Location: Location State: …DebugNN
45061Trace Information.DebugYN
45062Connection Paramters are Connection URI: Connection_URI Resource URI: …DebugNN
45063Workflow plugin loaded.AnalyticNN
45064Workflow execution started.AnalyticNN
45065Workflow state changed.AnalyticNN
45072Workflow plugin has been requested for a shutdown.AnalyticNN
45073Workflow plugin restarted.AnalyticNN
45074Workflow is resuming.AnalyticNN
45075A quota limit that was set for the endpoint was exceeded.AnalyticNN
45076Workflow has resumed.AnalyticNN
45078Workflow runspace pool was created.AnalyticNN
45079Activity was queued for execution.AnalyticNN
45080Activity execution started.AnalyticNN
45081Workflow is being imported from a XAML file.AnalyticNN
45082Workflow has been imported from a XAML file.AnalyticNN
45083Workflow could not be imported from a XAML file because of an error.AnalyticNN
45084Workflow validation started.AnalyticNN
45085Workflow validation succeeded.AnalyticNN
45086Workflow validation failed with error.AnalyticNN
45087Workflow activity validated.AnalyticNN
45088Workflow activity could not be validated.AnalyticNN
45089Activity execution failed.AnalyticNN
45090Runspace availability changed.AnalyticNN
45091Runspace state changed.AnalyticNN
45092Workflow loaded for execution.AnalyticNN
45093Workflow unloaded.AnalyticNN
45094Workflow execution cancelled.AnalyticNN
45095Workflow execution aborted.AnalyticNN
45096Workflow cleanup operation executed.AnalyticNN
45097Persisted workflow loaded from disk.AnalyticNN
45098Workflow data was deleted from disk.AnalyticNN
45100Starting remove job.AnalyticNN
45101Job state changed.AnalyticNN
45102Job error.AnalyticNN
45104Job created for workflow (child job).AnalyticNN
45105Parent job created for workflow.AnalyticNN
45106All required jobs were created for workflow execution.AnalyticNN
45107Child job removed for workflow.AnalyticNN
45108An error occurred while removing job.AnalyticNN
45109Loading workflow for execution.AnalyticNN
45110Workflow execution finished.AnalyticNN
45111Cancelling workflow execution.AnalyticNN
45112Aborting workflow execution.AnalyticNN
45113Unloading workflow.AnalyticNN
45114Forced workflow shutdown started.AnalyticNN
45115Forced workflow shutdown finished.AnalyticNN
45116An error occurred while forcefully shutting down a workflow.AnalyticNN
45117Persisting workflow to disk.AnalyticNN
45118Workflow persisted to disk.AnalyticNN
45119Activity execution finished.AnalyticNN
45120Workflow execution error.AnalyticNN
45121A new PowerShell endpoint was registered.AnalyticNN
45122Endpoint configuration modified.AnalyticNN
45123Endpoint configuration unregistered.AnalyticNN
45124Endpoint configuration disabled.AnalyticNN
45125Endpoint configuration enabled.AnalyticNN
45126Out of process runspace started.AnalyticNN
45127Parameter splatting was performed during workflow execution.AnalyticNN
45128Workflow engine started.AnalyticNN
45129Workflow manager instantiated with CheckpointPath: CheckpointPath …DebugNN
46337BEGIN ImportWorkflowCommand::StartWorkflowApplication.DebugNN
46338END ImportWorkflowCommand::StartWorkflowApplication.DebugNN
46339BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication.DebugNN
46340END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.DebugNN
46341END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.DebugNN
46342BEGIN JobLogic ContainerParentJob Guid WorkflowJobJobInstanceId.DebugNN
46343END JobLogic ContainerParentJob Guid WorkflowJobJobInstanceId.DebugNN
46344BEGIN WorkflowExecution ContainerParentJob Guid WorkflowJobJobInstanceId.DebugNN
46345END WorkflowExecution ContainerParentJob Guid WorkflowJobJobInstanceId.DebugNN
46346WorkflowJob with Guid WorkflowJobInstanceId added to ContainerParentJob with …DebugNN
46347ProxyJob with Guid ProxyJobInstanceId associated with remote ContainerParentJob …DebugNN
46348BEGIN Execution of ContainerParentJob with Guid ContainerParentJobInstanceId.DebugNN
46349END Execution of ContainerParentJob with Guid ContainerParentJobInstanceId.DebugNN
46350BEGIN Execution of Proxy Job with Guid ProxyJobInstanceId.DebugNN
46351END Execution of Proxy Job with Guid ProxyJobInstanceId.DebugNN
46352BEGIN StateChanged event handler for Proxy Job with Guid ProxyJobInstanceId.DebugNN
46353END StateChanged event handler for Proxy Job with Guid ProxyJobInstanceId.DebugNN
46354BEGIN StateChanged event handler for Proxy Child Job with Guid …DebugNN
46355END StateChanged event handler for Proxy Child Job with Guid …DebugNN
46356BEGIN Running garbage collectionDebugNN
46357END Running garbage collectionDebugNN
46358Persistence store has reached its maximum specified sizeOperationalNN
49152message.DebugNN
49153Trace Information.DebugNN
53249Scheduled Job ScheduledJobDefName started at StartTime.OperationalYN
53250Scheduled Job ScheduledJobDefName completed at StopTime with state State.OperationalYN
53251Scheduled Job Exception Message.OperationalNN
53504Windows PowerShell has started an IPC listening thread on process: param1 in …OperationalYN
53505Windows PowerShell has ended an IPC listening thread on process: param1 in …OperationalNN
53506An error has occurred in Windows PowerShell IPC listening thread on process: …OperationalNN
53507Windows PowerShell IPC connect on process: param1 in AppDomain: param2 for User: …OperationalNN
53508Windows PowerShell IPC disconnect on process: param1 in AppDomain: param2 for …OperationalNN

Event ID 4097: Computer Name $null or.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Computer Name $null or . resolve to LocalHost.

Message #

Computer Name $null or . resolve to LocalHost

Event ID 4098: Resolving to default scheme http

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Event ID 4099: Remote shell name resolved to default Microsoft.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Remote shell name resolved to default Microsoft.PowerShell.

Message #

Remote shell name resolved to default Microsoft.PowerShell

Event ID 4100: Payload Context: ContextInfo User Data: UserData.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security, others)
Opcode
Tobeusedwhenanexceptionisraised

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescription
ContextInfo UnicodeStringContext
UserData UnicodeString
Payload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 4100,
    "version": 1,
    "level": 3,
    "task": 106,
    "opcode": 19,
    "keywords": 0,
    "time_created": "2026-06-13T05:24:22.6461352+00:00",
    "event_record_id": 164816,
    "correlation": {
      "ActivityID": "{AA583517-FAF4-0001-383A-58AAF4FADC01}"
    },
    "execution": {
      "process_id": 7180,
      "thread_id": 7444
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "ContextInfo": "        Severity = Warning\n        Host Name = ConsoleHost\n        Host Version = 5.1.20348.558\n        Host ID = f5117d22-3ce1-45ff-8086-de5eb4591327\n        Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Bypass -NonInteractive -File C:\\ludus\\background\\set-bg.ps1\n        Engine Version = 5.1.20348.558\n        Runspace ID = d45fbe4a-06f2-475d-a9db-ab9fc6584c17\n        Pipeline ID = 1\n        Command Name = \n        Command Type = \n        Script Name = \n        Command Path = \n        Sequence Number = 19\n        User = cell-c\\domainadmin\n        Connected User = \n        Shell ID = Microsoft.PowerShell\n",
    "UserData": "",
    "Payload": "Error Message = System error.\n"
  },
  "message": "Error Message = System error.\r\n\r\n\r\nContext:\r\n        Severity = Warning\r\n        Host Name = ConsoleHost\r\n        Host Version = 5.1.20348.558\r\n        Host ID = f5117d22-3ce1-45ff-8086-de5eb4591327\r\n        Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Bypass -NonInteractive -File C:\\ludus\\background\\set-bg.ps1\r\n        Engine Version = 5.1.20348.558\r\n        Runspace ID = d45fbe4a-06f2-475d-a9db-ab9fc6584c17\r\n        Pipeline ID = 1\r\n        Command Name = \r\n        Command Type = \r\n        Script Name = \r\n        Command Path = \r\n        Sequence Number = 19\r\n        User = cell-c\\domainadmin\r\n        Connected User = \r\n        Shell ID = Microsoft.PowerShell\r\n\r\n\r\nUser Data:\r\n\r\n"
}

Event ID 4101: Payload Context: ContextInfo User Data: UserData.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Opcode
Tobeusedwhenanexceptionisraised

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "A0C1853B-5C40-4B15-8766-3CF1C58F985A",
    "event_source_name": "",
    "event_id": 4101,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 19,
    "keywords": 9223372036854775840,
    "time_created": "2026-03-13T19:32:29.608586+00:00",
    "event_record_id": 149117,
    "correlation": {
      "ActivityID": "DF92C490-B30B-000C-6802-93DF0BB3DC01"
    },
    "execution": {
      "process_id": 4068,
      "thread_id": 956
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "ContextInfo": "Install",
    "UserData": "Package=nuget, Version=2.8.5.208, Provider=Bootstrap, Source=https://cdn.oneget.org/providers/nuget-2.8.5.208.package.swidtag, Status=Installed, DestinationPath=",
    "Payload": "PackageManagement: A package is installed."
  },
  "message": ""
}

Event ID 4102: Payload Context: ContextInfo User Data: UserData.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security, others)
Opcode
Tobeusedwhenanexceptionisraised

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescription
ContextInfo UnicodeStringContext
UserData UnicodeString
Payload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 4102,
    "version": 1,
    "level": 3,
    "task": 106,
    "opcode": 19,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:40.9609813+00:00",
    "event_record_id": 291397,
    "correlation": {
      "ActivityID": "{C6821FB2-EF88-0004-5018-83C688EFDC01}"
    },
    "execution": {
      "process_id": 1152,
      "thread_id": 8008
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "ContextInfo": "        Severity = Warning\n        Host Name = ServerRemoteHost\n        Host Version = 1.0.0.0\n        Host ID = e8ecf392-16f7-461a-9e04-2cf3b693e616\n        Host Application = C:\\Windows\\system32\\wsmprovhost.exe -Embedding\n        Engine Version = 5.1.20348.558\n        Runspace ID = 7d22a55e-f35a-436b-aadc-c65ab73a8891\n        Pipeline ID = 4684\n        Command Name = \n        Command Type = \n        Script Name = \n        Command Path = \n        Sequence Number = 82234\n        User = cell-a\\domainadmin\n        Connected User = cell-a\\domainadmin\n        Shell ID = Microsoft.PowerShell\n",
    "UserData": "",
    "Payload": "Error Message = Could not find the drive 'Z:\\'. The drive might not be ready or might not be mapped.\n\nProvider name = Microsoft.PowerShell.Core\\FileSystem\n"
  },
  "message": "Error Message = Could not find the drive 'Z:\\'. The drive might not be ready or might not be mapped.\r\n\r\nProvider name = Microsoft.PowerShell.Core\\FileSystem\r\n\r\n\r\nContext:\r\n        Severity = Warning\r\n        Host Name = ServerRemoteHost\r\n        Host Version = 1.0.0.0\r\n        Host ID = e8ecf392-16f7-461a-9e04-2cf3b693e616\r\n        Host Application = C:\\Windows\\system32\\wsmprovhost.exe -Embedding\r\n        Engine Version = 5.1.20348.558\r\n        Runspace ID = 7d22a55e-f35a-436b-aadc-c65ab73a8891\r\n        Pipeline ID = 4684\r\n        Command Name = \r\n        Command Type = \r\n        Script Name = \r\n        Command Path = \r\n        Sequence Number = 82234\r\n        User = cell-a\\domainadmin\r\n        Connected User = cell-a\\domainadmin\r\n        Shell ID = Microsoft.PowerShell\r\n\r\n\r\nUser Data:\r\n\r\n"
}

Event ID 4103: Payload Context: ContextInfo User Data: UserData.

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Opcode
Tobeusedwhenanexceptionisraised

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescriptionRules
ContextInfo UnicodeStringContext315 detection rules
UserData UnicodeString
Payload UnicodeString400 detection rules

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 4103,
    "version": 1,
    "level": 4,
    "task": 106,
    "opcode": 20,
    "keywords": 0,
    "time_created": "2026-06-13T14:11:14.9015833+00:00",
    "event_record_id": 168285,
    "correlation": {
      "ActivityID": "{AA583517-FAF4-0000-BF5D-58AAF4FADC01}"
    },
    "execution": {
      "process_id": 7864,
      "thread_id": 1248
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "ContextInfo": "        Severity = Informational\n        Host Name = ServerRemoteHost\n        Host Version = 1.0.0.0\n        Host ID = aa212afc-f66e-4e09-a428-4989b19010a1\n        Host Application = C:\\Windows\\system32\\wsmprovhost.exe -Embedding\n        Engine Version = 5.1.20348.558\n        Runspace ID = 55ce38e0-81ea-44db-9a08-0c9965b78525\n        Pipeline ID = 10\n        Command Name = ConvertTo-Json\n        Command Type = Cmdlet\n        Script Name = \n        Command Path = \n        Sequence Number = 52\n        User = cell-c\\domainadmin\n        Connected User = cell-c\\domainadmin\n        Shell ID = Microsoft.PowerShell\n",
    "UserData": "",
    "Payload": "CommandInvocation(ConvertTo-Json): \"ConvertTo-Json\"\nParameterBinding(ConvertTo-Json): name=\"Depth\"; value=\"14\"\nParameterBinding(ConvertTo-Json): name=\"Compress\"; value=\"True\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\n"
  },
  "message": "CommandInvocation(ConvertTo-Json): \"ConvertTo-Json\"\r\nParameterBinding(ConvertTo-Json): name=\"Depth\"; value=\"14\"\r\nParameterBinding(ConvertTo-Json): name=\"Compress\"; value=\"True\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\nParameterBinding(ConvertTo-Json): name=\"InputObject\"; value=\"System.Collections.Specialized.OrderedDictionary\"\r\n\r\n\r\nContext:\r\n        Severity = Informational\r\n        Host Name = ServerRemoteHost\r\n        Host Version = 1.0.0.0\r\n        Host ID = aa212afc-f66e-4e09-a428-4989b19010a1\r\n        Host Application = C:\\Windows\\system32\\wsmprovhost.exe -Embedding\r\n        Engine Version = 5.1.20348.558\r\n        Runspace ID = 55ce38e0-81ea-44db-9a08-0c9965b78525\r\n        Pipeline ID = 10\r\n        Command Name = ConvertTo-Json\r\n        Command Type = Cmdlet\r\n        Script Name = \r\n        Command Path = \r\n        Sequence Number = 52\r\n        User = cell-c\\domainadmin\r\n        Connected User = cell-c\\domainadmin\r\n        Shell ID = Microsoft.PowerShell\r\n\r\n\r\nUser Data:\r\n\r\n"
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventDatacontains-itemproperty5 rulessigma
EventDatacontains.dll3 rulessigma
EventDatacontainsname3 rulessigma
EventDatacontainsset-mppreference3 rulessigma
EventDatacontains\system\currentcontrolset\services\2 rulessigma
EventDatacontainsadd-mppreference2 rulessigma
EventDatacontainsftp://2 rulessigma
Payloadcontains-itemproperty5 rulessigma
Payloadcontains.dll3 rulessigma
Payloadcontainsname3 rulessigma
ScriptBlockTextcontains-itemproperty5 rulessigma
ScriptBlockTextcontains.dll3 rulessigma
ScriptBlockTextcontainsname3 rulessigma
CommandLineregex_match(?i)\w+tps?://\S+\.msi2 rulessplunk
ContextInfocontainssystem.net.webclient2 rulessigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Splunk # view in coverage

References #

Event ID 4104: Creating Scriptblock text (MessageNumber of MessageTotal).

#
Channel
Operational
Also via
realtime ETW trace
Level
Verbose
Collection Priority
Recommended (Yamato Security, others)
Task
StartingCommand
Opcode
Oncreatecalls

Message #

Creating Scriptblock text (%1 of %2):
%3

ScriptBlock ID: %4
Path: %5

Fields #

NameDescriptionRules
MessageNumber Int32Part number of the current script block fragment (large scripts are split across multiple events)
MessageTotal Int32Total number of script block fragments for the complete script
ScriptBlockText UnicodeStringContent of the executed PowerShell script block1890 detection rules
ScriptBlockId UnicodeStringScriptBlock ID.
Path UnicodeStringFull path to the executed script file3 detection rules

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 4104,
    "version": 1,
    "level": 5,
    "task": 2,
    "opcode": 15,
    "keywords": 0,
    "time_created": "2026-06-13T14:11:14.9274534+00:00",
    "event_record_id": 168286,
    "correlation": {
      "ActivityID": "{AA583517-FAF4-0004-3DE7-58AAF4FADC01}"
    },
    "execution": {
      "process_id": 7864,
      "thread_id": 7844
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "MessageNumber": "1",
    "MessageTotal": "1",
    "ScriptBlockText": "Export-XmlVrecEvents -Channel 'Microsoft-Windows-LSA/Operational' -Max 8000",
    "ScriptBlockId": "f8e011c2-f02d-4ac3-9cd6-a7d76a3309eb",
    "Path": ""
  },
  "message": "Creating Scriptblock text (1 of 1):\r\nExport-XmlVrecEvents -Channel 'Microsoft-Windows-LSA/Operational' -Max 8000\r\n\r\nScriptBlock ID: f8e011c2-f02d-4ac3-9cd6-a7d76a3309eb\r\nPath: "
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ScriptBlockTextcontainsnew-object8 rulessigma, splunk
ScriptBlockTextcontainsget-wmiobject7 rulessigma, splunk
ScriptBlockTextcontains-itemproperty5 rulessigma
ScriptBlockTextcontains[adsisearcher]4 rulessplunk
ScriptBlockTextcontainsfrombase64string4 rulessigma, splunk
ScriptBlockTextcontainsget-aduser4 rulessigma, splunk
ScriptBlockTextcontainsget-childitem4 rulessigma
ScriptBlockTextcontainsget-netuser4 rulessplunk
ScriptBlockTextcontainsinvoke-restmethod4 rulessigma, splunk
ScriptBlockTextcontainsname4 rulessigma
Esql.script_block_lengthgt5006 ruleselastic
Esql.script_block_pattern_countge16 ruleselastic
EventDatacontains-itemproperty5 rulessigma
Payloadcontains-itemproperty5 rulessigma
file.directoryis_null5 ruleselastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Elastic # view in coverage

  • Potential AMSI Bypass via RPC Runtime Hooking source high: Identifies PowerShell script block content associated with an Antimalware Scan Interface (AMSI) bypass that hooks the RPC runtime marshaling stub NdrClientCall3 (or NdrClientCall2) in rpcrt4.dll. Unlike bypasses that patch AmsiScanBuffer or set amsiInitFailed, this technique operates at the RPC layer used by AMSI to delegate scan requests to the antivirus provider, tampering with the request before it reaches the engine and leaving AMSI itself unmodified. The loader allocates an executable trampoline and marshals a delegate to the native stub; these primitives appear in PowerShell Script Block Logging before the hook takes effect.T1059, T1059.001, T1562, T1562.001
  • Potential PowerShell Obfuscation via Invalid Escape Sequences source medium: Detects PowerShell scripts with repeated invalid backtick escapes between word characters (letters, digits, underscore, or dash), splitting tokens while preserving execution. Attackers use this obfuscation to fragment keywords and evade pattern-based detection and AMSI.T1027, T1027.010, T1059, T1059.001, T1140
  • Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion source high: Detects PowerShell scripts that use backtick-escaped characters inside ${} variable expansion (multiple backticks between word characters) to reconstruct strings at runtime. Attackers use variable-expansion obfuscation to split keywords, hide commands, and evade static analysis and AMSI.T1027, T1027.010, T1059, T1059.001, T1140

Splunk # view in coverage

  • AdsiSearcher Account Discovery source: The following analytic detects the use of the [Adsisearcher] type accelerator in PowerShell to query Active Directory for domain users. It leverages PowerShell Script Block Logging (EventCode=4104) to identify script blocks containing…T1087, T1087.002
  • Allow Inbound Traffic In Firewall Rule source: The following analytic detects a suspicious PowerShell command that allows inbound traffic to a specific local port within the public profile. It leverages PowerShell script block logging (EventCode 4104) to identify commands containing…T1021, T1021.001
  • Delete ShadowCopy With PowerShell source: The following analytic detects the use of PowerShell to delete shadow copies via the WMIC PowerShell module. It leverages EventCode 4104 and searches for specific keywords like "ShadowCopy," "Delete," or "Remove" within the…T1490

References #

Event ID 4105: Started invocation of ScriptBlock ID: ScriptBlockId.

#
Channel
Operational
Also via
realtime ETW trace
Level
Verbose
Collection Priority
Recommended (Microsoft-WEF, others)
Task
StartingCommand
Opcode
Open(async)

Message #

Started invocation of ScriptBlock ID: %1
Runspace ID: %2

Fields #

NameDescription
ScriptBlockId UnicodeStringStarted invocation of ScriptBlock ID.
RunspaceId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 4105,
    "version": 1,
    "level": 5,
    "task": 102,
    "opcode": 15,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:52.9762883+00:00",
    "event_record_id": 292345,
    "correlation": {
      "ActivityID": "{C6821FB2-EF88-0000-CDB8-82C688EFDC01}"
    },
    "execution": {
      "process_id": 4440,
      "thread_id": 3676
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "ScriptBlockId": "04d49ce2-3f05-45a9-957c-5758c9f59afd",
    "RunspaceId": "433997d9-ccc4-4c0d-bc9b-e1f7f9b3ed04"
  },
  "message": "Started invocation of ScriptBlock ID: 04d49ce2-3f05-45a9-957c-5758c9f59afd\r\nRunspace ID: 433997d9-ccc4-4c0d-bc9b-e1f7f9b3ed04"
}

References #

Event ID 4106: Completed invocation of ScriptBlock ID: ScriptBlockId.

#
Channel
Operational
Also via
realtime ETW trace
Level
Verbose
Collection Priority
Recommended (Microsoft-WEF, others)
Task
StoppingCommand
Opcode
Close(Async)

Message #

Completed invocation of ScriptBlock ID: %1
Runspace ID: %2

Fields #

NameDescription
ScriptBlockId UnicodeStringCompleted invocation of ScriptBlock ID.
RunspaceId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 4106,
    "version": 1,
    "level": 5,
    "task": 103,
    "opcode": 15,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:52.9776346+00:00",
    "event_record_id": 292349,
    "correlation": {
      "ActivityID": "{C6821FB2-EF88-0006-879F-82C688EFDC01}"
    },
    "execution": {
      "process_id": 4440,
      "thread_id": 7812
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "ScriptBlockId": "cfd3b61c-5457-44b3-aee3-bbfbd9689340",
    "RunspaceId": "b4551755-8da0-496c-9c88-6bf2955ba423"
  },
  "message": "Completed invocation of ScriptBlock ID: cfd3b61c-5457-44b3-aee3-bbfbd9689340\r\nRunspace ID: b4551755-8da0-496c-9c88-6bf2955ba423"
}

References #

Event ID 7937: ContextInfo Context: Context User Data: User_Data.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 7937,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 20,
    "keywords": "0x4000000000000020",
    "time_created": "2026-06-02T04:29:47.997+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0003-4D12-848753F0DC01}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 3636
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ContextInfo": "        Severity = Informational\r\n        Host Name = ConsoleHost\r\n        Host Version = 5.1.20348.4294\r\n        Host ID = 2b5c509a-8716-4b8e-9e7b-d73a2aa98dcd\r\n        Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File C:\\Tools\\Sealighter\\drv\\drv04.ps1\r\n        Engine Version = 5.1.20348.4294\r\n        Runspace ID = 2d8a8c17-0da2-4dfe-a42d-bebe964bcedb\r\n        Pipeline ID = 1\r\n        Command Name = Start-Job\r\n        Command Type = Cmdlet\r\n        Script Name = C:\\Tools\\Sealighter\\drv\\drv04.ps1\r\n        Command Path = \r\n        Sequence Number = 721\r\n        User = ludus\\domainadmin\r\n        Connected User = \r\n        Shell ID = Microsoft.PowerShell\r\n",
    "Payload": "Command System.Management.Automation.LogContext is Stopped.\r\n",
    "UserData": ""
  },
  "message": "win:None"
}

Event ID 7938: Payload Context: ContextInfo User Data: UserData.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": "7938",
    "version": "1",
    "level": "4",
    "task": "100",
    "opcode": "20",
    "keywords": 0,
    "time_created": "2026-03-15T04:33:37.067269800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{d73f5340-b345-0001-748f-44d745b3dc01}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "12172"
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ContextInfo": "        Severity = Informational\n        Host Name = ConsoleHost\n        Host Version = 5.1.20348.558\n        Host ID = 247af873-a1bf-4dba-9ce9-5140eb54ab09\n        Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Bypass -File C:\\Users\\domainadmin\\Desktop\\automaton\\onedrive_etw_capture.ps1 -Action stop\n        Engine Version = 5.1.20348.558\n        Runspace ID = 83d77211-d444-44c5-9530-51739db0c2f4\n        Pipeline ID = \n        Command Name = \n        Command Type = \n        Script Name = \n        Command Path = \n        Sequence Number = 14\n        User = ludus\\domainadmin\n        Connected User = \n        Shell ID = Microsoft.PowerShell\n",
    "UserData": "",
    "Payload": "Engine state changed from None to Available.\n"
  },
  "message": ""
}

Event ID 7939: Payload Context: ContextInfo User Data: UserData.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": "7939",
    "version": "1",
    "level": "4",
    "task": "104",
    "opcode": "20",
    "keywords": 0,
    "time_created": "2026-03-15T04:33:36.400594000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{d73f5340-b345-0001-748f-44d745b3dc01}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "8064"
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ContextInfo": "        Severity = Informational\n        Host Name = ConsoleHost\n        Host Version = 5.1.20348.558\n        Host ID = 247af873-a1bf-4dba-9ce9-5140eb54ab09\n        Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Bypass -File C:\\Users\\domainadmin\\Desktop\\automaton\\onedrive_etw_capture.ps1 -Action stop\n        Engine Version = \n        Runspace ID = \n        Pipeline ID = \n        Command Name = \n        Command Type = \n        Script Name = \n        Command Path = \n        Sequence Number = 2\n        User = ludus\\domainadmin\n        Connected User = \n        Shell ID = Microsoft.PowerShell\n",
    "UserData": "",
    "Payload": "Provider Registry changed state to Started.\n"
  },
  "message": ""
}

Event ID 7940: ContextInfo Context: Context User Data: User_Data.

#
Channel
Analytic
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Payload Context: ContextInfo User Data: UserData

Message #

%3

Context:
%1

User Data:
%2

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 7941: Correlating activity id's.

#
Channel
Analytic
Task
win:None
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Correlating activity id's. 
 	 CurrentActivityId: %1 
 	 ParentActivityId: %2

Fields #

NameDescription
currentActivityId GUID
parentActivityId GUID

Event ID 7942: Class Name = ClassName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Class Name = %1
Method Name = %2
Workflow GUID = %3
Message = %4
%5
Activity Name = %6
Activity GUID = %7
Parameters = %8

Fields #

NameDescription
ClassName UnicodeString
MethodName UnicodeString
WorkflowGuid UnicodeString
Message UnicodeString
JobData UnicodeString
ActivityName UnicodeString
ActivityGuid UnicodeString
Parameters UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": "7942",
    "version": "1",
    "level": "5",
    "task": "0",
    "opcode": "20",
    "keywords": 0,
    "time_created": "2026-03-15T04:33:36.215006100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{d73f5340-b345-0001-748f-44d745b3dc01}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "12008"
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ClassName": "RemoteSessionNamedPipeServer",
    "MethodName": "StartListening",
    "WorkflowGuid": "00000000-0000-0000-0000-000000000000",
    "Message": "Listener thread started on Process 5820 in AppDomainName DefaultAppDomain.",
    "JobData": "",
    "ActivityName": "",
    "ActivityGuid": "",
    "Parameters": ""
  },
  "message": ""
}

Event ID 8193: Creating Runspace object Instance Id.

#
Channel
Operational
Level
Verbose
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
tobeusedwhenanobjectisconstructed

Description

Creating Runspace object.

Message #

Creating Runspace object 
 	 Instance Id: %1

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 8193,
    "version": 1,
    "level": 5,
    "task": 1,
    "opcode": 16,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:52.2119349+00:00",
    "event_record_id": 292217,
    "correlation": {
      "ActivityID": "{423FC9FF-BB95-4958-9E72-EC0DE8F5F539}"
    },
    "execution": {
      "process_id": 1152,
      "thread_id": 8008
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "423fc9ff-bb95-4958-9e72-ec0de8f5f539"
  },
  "message": "Creating Runspace object \r\n \t Instance Id: 423fc9ff-bb95-4958-9e72-ec0de8f5f539"
}

Event ID 8194: Creating RunspacePool object.

#
Channel
Operational
Level
Verbose
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
tobeusedwhenanobjectisconstructed

Message #

Creating RunspacePool object 
 	 InstanceId %1 
 	 MinRunspaces %2 
 	 MaxRunspaces %3

Fields #

NameDescription
InstanceId UnicodeString
MaxRunspaces UnicodeString
MinRunspaces UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 8194,
    "version": 1,
    "level": 5,
    "task": 1,
    "opcode": 16,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:52.2119503+00:00",
    "event_record_id": 292218,
    "correlation": {
      "ActivityID": "{93B2B5D3-AD4A-47FD-88FE-256547248572}"
    },
    "execution": {
      "process_id": 1152,
      "thread_id": 8008
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "InstanceId": "93b2b5d3-ad4a-47fd-88fe-256547248572",
    "MaxRunspaces": "1",
    "MinRunspaces": "1"
  },
  "message": "Creating RunspacePool object \r\n \t InstanceId 93b2b5d3-ad4a-47fd-88fe-256547248572 \r\n \t MinRunspaces 1 \r\n \t MaxRunspaces 1"
}

Event ID 8195: Opening RunspacePool

#
Channel
Operational
Level
Verbose
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Open(async)

Fields #

NameDescription
async)_V1(

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 8195,
    "version": 1,
    "level": 5,
    "task": 1,
    "opcode": 10,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:52.2121570+00:00",
    "event_record_id": 292219,
    "correlation": {
      "ActivityID": "{93B2B5D3-AD4A-47FD-88FE-256547248572}"
    },
    "execution": {
      "process_id": 1152,
      "thread_id": 8008
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": "Opening RunspacePool"
}

Event ID 8196: Modifying activity Id and correlating

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Open(async)

Fields #

NameDescription
async)8196_V1(

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 8196,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 20,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:52.9782661+00:00",
    "event_record_id": 292350,
    "correlation": {
      "ActivityID": "{93B2B5D3-AD4A-47FD-88FE-256547248572}"
    },
    "execution": {
      "process_id": 1152,
      "thread_id": 1496
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": "Modifying activity Id and correlating"
}

Event ID 8197: Runspace state changed to param1.

#
Channel
Operational
Also via
realtime ETW trace
Level
Verbose
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Open(async)

Message #

Runspace state changed to %1

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "A0C1853B-5C40-4B15-8766-3CF1C58F985A",
    "event_source_name": "",
    "event_id": 8197,
    "version": 1,
    "level": 5,
    "task": 1,
    "opcode": 10,
    "keywords": 0,
    "time_created": "2026-03-13T19:06:18.830885+00:00",
    "event_record_id": 451785,
    "correlation": {
      "ActivityID": "E345B8F4-8ABD-45C2-9C94-77A035AE705C"
    },
    "execution": {
      "process_id": 8572,
      "thread_id": 13812
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "Closing"
  },
  "message": ""
}

Event ID 8198: Attempting session creation retry param1 for error code param2 on session Id param3.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Open(async)

Message #

Attempting session creation retry %1 for error code %2 on session Id %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 12033: Port resolved to param1.

#
Channel
Analytic
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Port resolved to %1

Fields #

NameDescription
param1 UnicodeString

Event ID 12034: AppName resolved to param1.

#
Channel
Analytic
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

AppName resolved to %1

Fields #

NameDescription
param1 UnicodeString

Event ID 12035: ComputerName resolved to param1.

#
Channel
Analytic
Level
Verbose
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

ComputerName resolved to %1

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": 12035,
    "version": 1,
    "level": 5,
    "task": 1,
    "opcode": 20,
    "keywords": "0x4000000000000001",
    "time_created": "2026-07-19T03:43:55.444451600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "BF440000-0BF1-0006-D868-4CBFF10BDD01"
    },
    "execution": {
      "process_id": 7772,
      "thread_id": 5988
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "localhost"
  },
  "message": "ComputerName resolved to localhost"
}

Event ID 12036: Scheme is param1.

#
Channel
Analytic
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Scheme is %1

Fields #

NameDescription
param1 UnicodeString

Event ID 12037: Test analytic message

#
Channel
Analytic
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Event ID 12038: Connection Paramters are Connection URI: Connection_URI Resource URI: Resource_URI User: User OpenTimeout: OpenTimeout IdleTimeout: IdleTimeout CancelTimeout: CancelTimeout AuthenticationMechanism:...

#
Channel
Analytic
Task
Connect
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Connection Paramters are.

Message #

Connection Paramters are 
 Connection URI: %1 
 Resource URI: %2 
 User: %3 
 OpenTimeout: %4 
 IdleTimeout: %5 
 CancelTimeout: %6 
 AuthenticationMechanism: %7 
 Thumb Print: %8 
 MaxUriRedirectionCount: %9 
 MaxReceivedDataSizePerCommand: %10 
 MaxReceivedObjectSize: %11

Fields #

NameDescription
uri UnicodeString
shell UnicodeString
userName UnicodeString
opentimeout UnicodeString
idletimeout UnicodeString
canceltimeout UnicodeString
auth UInt32
Known values
0
Default - use the default authentication defined by the underlying protocol
1
Basic - use Basic authentication (credentials sent in clear text)
2
Negotiate - use Negotiate authentication for the remote connection
3
NegotiateWithImplicitCredential - use Negotiate with implicit credentials
4
CredSSP - use Credential Security Support Provider authentication
5
Digest - use Digest authentication (credentials sent as a hash value)
6
Kerberos - use Kerberos mutual authentication with certificates
thumbPrint UnicodeString
redircount UnicodeString
recvdDataSize UnicodeString
recvdObjSize UnicodeString

Event ID 12039: Modifying activity Id and correlating

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Connect
Opcode
Open(async)

Fields #

NameDescription
async)12039_V1(

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 12039,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 20,
    "keywords": 0,
    "time_created": "2026-06-13T14:36:52.9782673+00:00",
    "event_record_id": 292351,
    "correlation": {
      "ActivityID": "{93B2B5D3-AD4A-47FD-88FE-256547248572}"
    },
    "execution": {
      "process_id": 1152,
      "thread_id": 1496
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": "Modifying activity Id and correlating"
}

Event ID 16385: AmsiUtil state.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
AmsiState
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

AmsiUtil state. 
 	 state: %1 
 	 Context: %2

Fields #

NameDescription
Action UnicodeString
AmsiContext UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 16385,
    "version": 1,
    "level": 5,
    "task": 130,
    "opcode": 20,
    "keywords": "0x4000000000000400",
    "time_created": "2026-06-02T04:29:48.009+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 12528,
      "thread_id": 15844
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Action": "init-False",
    "AmsiContext": "1776513328784-26365"
  },
  "message": "Amsi"
}

Event ID 24577: Windows PowerShell ISE has started to run script file FileName.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Message #

Windows PowerShell ISE has started to run script file %1.

Fields #

NameDescription
FileName UnicodeString

Event ID 24578: Windows PowerShell ISE has started to run a user-selected script from file FileName.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Message #

Windows PowerShell ISE has started to run a user-selected script from file %1.

Fields #

NameDescription
FileName UnicodeString

Event ID 24579: Windows PowerShell ISE is stopping the current command.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24580: Windows PowerShell ISE is resuming the debugger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24581: Windows PowerShell ISE is stopping the debugger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24582: Windows PowerShell ISE is stepping into debugging.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24583: Windows PowerShell ISE is stepping over debugging.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24584: Windows PowerShell ISE is stepping out of debugging.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24592: Windows PowerShell ISE is enabling all breakpoints.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24593: Windows PowerShell ISE is disabling all breakpoints.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Event ID 24594: Windows PowerShell ISE is removing all breakpoints.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Event ID 24595: Windows PowerShell ISE is setting the breakpoint at line #: CurrentLine of file FileName.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Message #

Windows PowerShell ISE is setting the breakpoint at line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24596: Windows PowerShell ISE is removing the breakpoint on line #: CurrentLine of file FileName.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Message #

Windows PowerShell ISE is removing the breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24597: Windows PowerShell ISE is enabling the breakpoint on line #: CurrentLine of file FileName.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Message #

Windows PowerShell ISE is enabling the breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24598: Windows PowerShell ISE is disabling the breakpoint on line #: CurrentLine of file FileName.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Message #

Windows PowerShell ISE is disabling the breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24599: Windows PowerShell ISE has hit a breakpoint on line #: CurrentLine of file FileName.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellISEOperation

Message #

Windows PowerShell ISE has hit a breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 28673: Successfully rehydrated an object.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
Serializeordeserializeremotingpayload
Opcode
Rehydration

Message #

Successfully rehydrated an object. 
 	 Deserialized type name: %1 
 	 Rehydrated by casting to type: %2 
 	 Rehydrated object is of type: %3

Fields #

NameDescription
DeserializedType UnicodeString
CastedToType UnicodeString
RehydratedType UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 28673,
    "version": 1,
    "level": 5,
    "task": 3,
    "opcode": 23,
    "keywords": "0x4000000000000040",
    "time_created": "2026-06-02T04:29:48.126+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 7116
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CastedToType": "Microsoft.PowerShell.DeserializingTypeConverter",
    "DeserializedType": "Deserialized.System.Management.Automation.PSPrimitiveDictionary@@@Deserialized.System.Collections.Hashtable@@@Deserialized.System.Object",
    "RehydratedType": "System.Management.Automation.PSPrimitiveDictionary"
  },
  "message": "Serialization"
}

Event ID 28674: Failed to rehydrated an object.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Rehydration

Message #

Failed to rehydrated an object. 
 	 Deserialized type name: %1 
 	 Rehydrated by casting to type: %2 
 	 Type cast exception: %3 
 	 Type cast inner exception: %4

Fields #

NameDescription
DeserializedType UnicodeString
CastedToType UnicodeString
TypeCastException UnicodeString
TypeCastInnerException UnicodeString

Event ID 28675: Serialization depth has been overriden.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Serializationsettings

Message #

Serialization depth has been overriden. 
 	 Serialized type name: %1 
 	 Original depth: %2 
 	 Overriden depth: %3 
 	 Current depth below top level: %4

Fields #

NameDescription
SerializedType UnicodeString
OriginalDepth Int32
OverridenDepth Int32
CurrentDepthBelowTopLevel Int32

Event ID 28676: Serialization mode has been overriden.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Serializationsettings

Message #

Serialization mode has been overriden. 
 	 Serialized type name: %1 
 	 Overriden mode: %2

Fields #

NameDescription
SerializedType UnicodeString
OverridenMode UInt32

Event ID 28677: Serialization of a script property has been skipped, because there is no runspace to use for evaluation of the property.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Tobeusedwhenanexceptionisraised

Message #

Serialization of a script property has been skipped, because there is no runspace to use for evaluation of the property. 
 	 Property name: %1 
 	 Property owner's type name: %2 
 	 Getter script: %3

Fields #

NameDescription
PropertyName UnicodeString
PropertyOwnerType UnicodeString
GetterScript UnicodeString

Event ID 28678: Serialization of a property has been skipped, because property getter failed.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Tobeusedwhenanexceptionisraised

Message #

Serialization of a property has been skipped, because property getter failed. 
 	 Property name: %1 
 	 Property owner's type name: %2 
 	 Exception from property getter: %3 
 	 Inner exception from property getter: %4

Fields #

NameDescription
PropertyName UnicodeString
PropertyOwnerType UnicodeString
Exception UnicodeString
InnerException UnicodeString

Event ID 28679: Serialization of an enumerable object might not be complete, because object being enumerated threw an exception.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Tobeusedwhenanexceptionisraised

Message #

Serialization of an enumerable object might not be complete, because object being enumerated threw an exception. 
 	 Type of object being enumerated: %1 
 	 Exception: %2

Fields #

NameDescription
TypeBeingEnumerated UnicodeString
Exception UnicodeString

Event ID 28680: Serialization called object's ToString method which failed.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Tobeusedwhenanexceptionisraised

Message #

Serialization called object's ToString method which failed. 
 	 Type of object: %1 
 	 Exception: %2

Fields #

NameDescription
Type UnicodeString
Exception UnicodeString

Event ID 28682: Maximum depth below top level has been reached, forcing object to be serialized as strings.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Tobeusedwhenanexceptionisraised

Message #

Maximum depth below top level has been reached, forcing object to be serialized as strings. 
 	 Object type at max depth: %1 
 	 Property name at max depth: %2 
 	 Depth: %3

Fields #

NameDescription
TypeOfObjectAtMaxDepth UnicodeString
PropertyNameAtMaxDepth UnicodeString
Depth Int32

Event ID 28683: XmlException has been thrown by the deserializer (most likely indicating incorrect clixml format).

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Tobeusedwhenanexceptionisraised

Message #

XmlException has been thrown by the deserializer (most likely indicating incorrect clixml format). 
 	 Line number: %1 Line position: %2 
 	 Exception: %3

Fields #

NameDescription
LineNumber Int32
LinePosition Int32
Exception UnicodeString

Event ID 28684: Serialization of specified properties failed, because one of the specified properties was missing.

#
Channel
Analytic
Task
Serializeordeserializeremotingpayload
Opcode
Tobeusedwhenanexceptionisraised

Message #

Serialization of specified properties failed, because one of the specified properties was missing. 
 	 Type of object: %1 
 	 Property name: %2

Fields #

NameDescription
TypeOfObjectWithMissingProperty UnicodeString
PropertyName UnicodeString

Event ID 32769: Received object with Runspace Id: Runspace_InstanceId Command Id: PowerShell_InstanceId Destination: Destination DataType: DataType TargetInterface: TargetInterface.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Receive(Async)

Message #

Received object with Runspace Id: %1 Command Id: %2 Destination: %3 DataType: %4 TargetInterface: %5

Fields #

NameDescription
Runspace_InstanceId UnicodeString
PowerShell_InstanceId UnicodeString
Destination UInt32
Known values
1
Client - message is targeted to the client (sent by server)
2
Server - message is targeted to the server (sent by client)
DataType UInt32
Known values
65538
SESSION_CAPABILITY (0x00010002) - Session capability; bidirectional
65540
INIT_RUNSPACEPOOL (0x00010004) - Initialize RunspacePool; client to server
65541
PUBLIC_KEY (0x00010005) - Public key; client to server
65542
ENCRYPTED_SESSION_KEY (0x00010006) - Encrypted session key; server to client
65543
PUBLIC_KEY_REQUEST (0x00010007) - Public key request; server to client
65544
CONNECT_RUNSPACEPOOL (0x00010008) - Connect to a RunspacePool; client to server
135170
SET_MAX_RUNSPACES (0x00021002) - Set maximum runspaces; client to server
135171
SET_MIN_RUNSPACES (0x00021003) - Set minimum runspaces; client to server
135172
RUNSPACE_AVAILABILITY (0x00021004) - Runspace availability response; server to client
135173
RUNSPACEPOOL_STATE (0x00021005) - RunspacePool state info; server to client
135174
CREATE_PIPELINE (0x00021006) - Create and invoke pipeline; client to server
135175
GET_AVAILABLE_RUNSPACES (0x00021007) - Get available runspace count; client to server
135176
USER_EVENT (0x00021008) - User-defined event; server to client
135177
APPLICATION_PRIVATE_DATA (0x00021009) - Application private data; server to client
135178
GET_COMMAND_METADATA (0x0002100A) - Get command metadata; client to server
135179
RUNSPACEPOOL_INIT_DATA (0x0002100B) - RunspacePool initialization data; server to client
135180
RESET_RUNSPACE_STATE (0x0002100C) - Reset RunspacePool runspace state; client to server
135424
RUNSPACEPOOL_HOST_CALL (0x00021100) - Host method call on RunspacePool; server to client
135425
RUNSPACEPOOL_HOST_RESPONSE (0x00021101) - Host call response for RunspacePool; client to server
266242
PIPELINE_INPUT (0x00041002) - Pipeline input; client to server
266243
END_OF_PIPELINE_INPUT (0x00041003) - Close pipeline input collection; client to server
266244
PIPELINE_OUTPUT (0x00041004) - Pipeline output; server to client
266245
ERROR_RECORD (0x00041005) - Pipeline error record; server to client
266246
PIPELINE_STATE (0x00041006) - Pipeline state info; server to client or RunspacePool
266247
DEBUG_RECORD (0x00041007) - Pipeline debug record; server to client
266248
VERBOSE_RECORD (0x00041008) - Pipeline verbose record; server to client
266249
WARNING_RECORD (0x00041009) - Pipeline warning record; server to client
266256
PROGRESS_RECORD (0x00041010) - Pipeline progress record; server to client
266257
INFORMATION_RECORD (0x00041011) - Pipeline information record; server to client
266496
PIPELINE_HOST_CALL (0x00041100) - Host method call on pipeline; server to client
266497
PIPELINE_HOST_RESPONSE (0x00041101) - Host call response for pipeline; client to server
TargetInterface UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32769,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 10,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.018+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0000-F6D5-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 15220,
      "thread_id": 4892
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DataType": 65538,
    "Destination": 2,
    "PowerShell_InstanceId": "00000000-0000-0000-0000-000000000000",
    "Runspace_InstanceId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569",
    "TargetInterface": 1
  },
  "message": "win:None"
}

Event ID 32775: An unhandled exception occurred in the appdomain.

#
Channel
Analytic
Task
win:None
Opcode
Open(async)

Message #

An unhandled exception occurred in the appdomain. 
Exception Type: %1 
Exception Message: %2 
Exception StackTrace: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32776: Runspace Id: SessionId Pipeline Id: PipelineId.

#
Channel
Analytic
Level
Error
Task
win:None
Opcode
Open(async)

Description

Runspace Id: SessionId Pipeline Id: PipelineId. WSMan reported an error with error code: ErrorCode.

Message #

Runspace Id: %1 Pipeline Id: %2. WSMan reported an error with error code: %3. 
 Error message: %4 
 StackTrace: %5

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString
ErrorCode UnicodeString
ErrorMessage UnicodeString
StackTrace UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": 32776,
    "version": 1,
    "level": 2,
    "task": 0,
    "opcode": 10,
    "keywords": "0x4000000000000008",
    "time_created": "2026-07-19T03:43:55.546539100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "803301C6-C5C2-42AC-B447-3665E7821E42"
    },
    "execution": {
      "process_id": 7772,
      "thread_id": 7616
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "SessionId": "803301c6-c5c2-42ac-b447-3665e7821e42",
    "PipelineId": "00000000-0000-0000-0000-000000000000",
    "ErrorCode": "5",
    "ErrorMessage": "Connecting to remote server localhost failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic.",
    "StackTrace": ""
  },
  "message": "Runspace Id: 803301c6-c5c2-42ac-b447-3665e7821e42 Pipeline Id: 00000000-0000-0000-0000-000000000000. WSMan reported an error with error code: 5. \n Error message: Connecting to remote server localhost failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic. \n StackTrace:"
}

Event ID 32777: An unhandled exception occurred in the appdomain.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
win:None
Opcode
Open(async)

Message #

An unhandled exception occurred in the appdomain. 
Exception Type: %1 
Exception Message: %2 
Exception StackTrace: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32784: Runspace Id: SessionId Pipeline Id: PipelineId.

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)
Task
win:None
Opcode
Open(async)

Description

Runspace Id: SessionId Pipeline Id: PipelineId. WSMan reported an error with error code: ErrorCode.

Message #

Runspace Id: %1 Pipeline Id: %2. WSMan reported an error with error code: %3. 
 Error message: %4 
 StackTrace: %5

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString
ErrorCode UnicodeString
ErrorMessage UnicodeString
StackTrace UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "A0C1853B-5C40-4B15-8766-3CF1C58F985A",
    "event_source_name": "",
    "event_id": 32784,
    "version": 1,
    "level": 2,
    "task": 0,
    "opcode": 10,
    "keywords": 0,
    "time_created": "2026-03-13T19:48:48.051299+00:00",
    "event_record_id": 692957,
    "correlation": {
      "ActivityID": "0DB6BBF5-303D-4E93-8DE3-887C047E8B68"
    },
    "execution": {
      "process_id": 1512,
      "thread_id": 1452
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "0db6bbf5-303d-4e93-8de3-887c047e8b68",
    "PipelineId": "00000000-0000-0000-0000-000000000000",
    "ErrorCode": "-2144108101",
    "ErrorMessage": "Connecting to remote server 10.2.10.21 failed with the following error message : The WinRM client cannot process the request. Default authentication may be used with an IP address under the following conditions: the transport is HTTPS or the destination is in the TrustedHosts list, and explicit credentials are provided. Use winrm.cmd to configure TrustedHosts. Note that computers in the TrustedHosts list might not be authenticated. For more information on how to set TrustedHosts run the following command: winrm help config. For more information, see the about_Remote_Troubleshooting Help topic.",
    "StackTrace": ""
  },
  "message": ""
}

Event ID 32785: Runspace Id param1.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
connect

Description

Runspace Id param1. Establishing a connection using WSMan Create Shell.

Message #

Runspace Id %1. Establishing a connection using WSMan Create Shell

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32785,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 10,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T05:29:54.150+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0008-D88F-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 10052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": ""
  },
  "message": "win:None"
}

Event ID 32786: Runspace Id param1.

#
Channel
Analytic
Level
Informational
Task
win:None
Opcode
connect

Description

Runspace Id param1. Callback received for WSMan Create Shell.

Message #

Runspace Id %1. Callback received for WSMan Create Shell

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": 32786,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 12,
    "keywords": "0x4000000000000008",
    "time_created": "2026-07-19T03:43:55.545843500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "803301C6-C5C2-42AC-B447-3665E7821E42"
    },
    "execution": {
      "process_id": 7772,
      "thread_id": 1908
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "803301c6-c5c2-42ac-b447-3665e7821e42"
  },
  "message": "Runspace Id 803301c6-c5c2-42ac-b447-3665e7821e42. Callback received for WSMan Create Shell"
}

Event ID 32787: Runspace Id: RunspaceId.

#
Channel
Analytic
Level
Informational
Task
win:None
Opcode
Disconnect

Description

Runspace Id: RunspaceId. Closing shell using WSManCloseShell.

Message #

Runspace Id: %1. Closing shell using WSManCloseShell

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": 32787,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 13,
    "keywords": "0x4000000000000008",
    "time_created": "2026-07-19T03:43:55.546627400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "803301C6-C5C2-42AC-B447-3665E7821E42"
    },
    "execution": {
      "process_id": 7772,
      "thread_id": 7616
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "803301c6-c5c2-42ac-b447-3665e7821e42"
  },
  "message": "Runspace Id: 803301c6-c5c2-42ac-b447-3665e7821e42. Closing shell using WSManCloseShell"
}

Event ID 32788: Runspace Id: RunspaceId.

#
Channel
Analytic
Level
Informational
Task
win:None
Opcode
Disconnect

Description

Runspace Id: RunspaceId. Callback received for WSManCloseShell.

Message #

Runspace Id: %1. Callback received for WSManCloseShell

Fields #

NameDescription
param1 UnicodeString
win:ExtraPayload

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{a0c1853b-5c40-4b15-8766-3cf1c58f985a}",
    "event_source_name": "",
    "event_id": 32788,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 13,
    "keywords": "0x4000000000000008",
    "time_created": "2026-07-19T03:43:55.546724600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "803301C6-C5C2-42AC-B447-3665E7821E42"
    },
    "execution": {
      "process_id": 7772,
      "thread_id": 7616
    },
    "channel": "Microsoft-Windows-PowerShell/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "803301c6-c5c2-42ac-b447-3665e7821e42",
    "win:ExtraPayload": "0x4F006E0043006C006F0073006500530065007300730069006F006E0043006F006D0070006C0065007400650064000000"
  },
  "message": "Runspace Id: 803301c6-c5c2-42ac-b447-3665e7821e42. Callback received for WSManCloseShell"
}

Event ID 32789: Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Send(Async)

Description

Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id. Sending data of size SessionId.

Message #

Runspace Id: %1 Pipeline Id: %2. Sending data of size %3

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString
DataSize UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32789,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 21,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.128+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 7116
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DataSize": "2480",
    "PipelineId": "ba938c13-e497-4b6f-8de6-08b164dd5a82",
    "SessionId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569"
  },
  "message": "win:None"
}

Event ID 32790: Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Send(Async)

Description

Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id. Callback received for WSManSendShellInputEx.

Message #

Runspace Id: %1 Pipeline Id: %2. Callback received for WSManSendShellInputEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32790,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 12,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.126+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 7116
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PipelineId": "00000000-0000-0000-0000-000000000000",
    "SessionId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569"
  },
  "message": "win:None"
}

Event ID 32791: Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.

#
Channel
Analytic
Task
win:None
Opcode
Receive(Async)

Description

Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id. Placing Receive request using WSManReceiveShellOutputEx.

Message #

Runspace Id: %1 Pipeline Id: %2. Placing Receive request using WSManReceiveShellOutputEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Event ID 32792: Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Receive(Async)

Description

Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id. Received Data of size SessionId.

Message #

Runspace Id: %1 Pipeline Id: %2. Received Data of size %3.

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString
DataSize UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32792,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 22,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.022+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 7116
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DataSize": "223",
    "PipelineId": "00000000-0000-0000-0000-000000000000",
    "SessionId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569"
  },
  "message": "win:None"
}

Event ID 32793: Runspace Id SessionId Pipeline Id PipelineId.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
connect

Description

Runspace Id SessionId Pipeline Id PipelineId. Establishing a command connection using WSManRunShellCommandEx.

Message #

Runspace Id %1 Pipeline Id %2. Establishing a command connection using WSManRunShellCommandEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32793,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 12,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.127+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 8196
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PipelineId": "ba938c13-e497-4b6f-8de6-08b164dd5a82",
    "SessionId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569"
  },
  "message": "win:None"
}

Event ID 32800: Runspace Id SessionId Pipeline Id PipelineId.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
connect

Description

Runspace Id SessionId Pipeline Id PipelineId. Callback received for command connection.

Message #

Runspace Id %1 Pipeline Id %2. Callback received for command connection

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32800,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 12,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.128+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 7116
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PipelineId": "ba938c13-e497-4b6f-8de6-08b164dd5a82",
    "SessionId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569"
  },
  "message": "win:None"
}

Event ID 32801: Runspace Id: Runspace_Id Pipeline Id SessionId.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Disconnect

Description

Runspace Id: Runspace_Id Pipeline Id SessionId. Closing transport for command.

Message #

Runspace Id: %1 Pipeline Id %2. Closing transport for command

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32801,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 13,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.131+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 9420
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PipelineId": "ba938c13-e497-4b6f-8de6-08b164dd5a82",
    "SessionId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569"
  },
  "message": "win:None"
}

Event ID 32802: Runspace Id: Runspace_Id Pipeline Id SessionId.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Disconnect

Description

Runspace Id: Runspace_Id Pipeline Id SessionId. Callback received for command close.

Message #

Runspace Id: %1 Pipeline Id %2. Callback received for command close

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32802,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 13,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.131+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E3450CF8-EBFD-44C7-97D8-B6C7C3DA8569}"
    },
    "execution": {
      "process_id": 7868,
      "thread_id": 7116
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PipelineId": "ba938c13-e497-4b6f-8de6-08b164dd5a82",
    "SessionId": "e3450cf8-ebfd-44c7-97d8-b6c7c3da8569"
  },
  "message": "win:None"
}

Event ID 32803: Runspace Id: Runspace_Id Pipeline Id SessionId.

#
Channel
Analytic
Task
win:None
Opcode
Disconnect

Description

Runspace Id: Runspace_Id Pipeline Id SessionId. Sending signal with code PipelineId using WSManSignalShellEx.

Message #

Runspace Id: %1 Pipeline Id %2. Sending signal with code %3 using WSManSignalShellEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString
SignalCode UnicodeString

Event ID 32804: Runspace Id: Runspace_Id Pipeline Id SessionId.

#
Channel
Analytic
Task
win:None
Opcode
Disconnect

Description

Runspace Id: Runspace_Id Pipeline Id SessionId. Callback received for WSManSignalShellEx.

Message #

Runspace Id: %1 Pipeline Id %2. Callback received for WSManSignalShellEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Event ID 32805: Runspace Id: SessionId.

#
Channel
Analytic
Task
win:None
Opcode
connect

Description

Runspace Id: SessionId. Connection is getting redirected to Uri: Uri.

Message #

Runspace Id: %1. Connection is getting redirected to Uri: %2

Fields #

NameDescription
SessionId UnicodeString
Uri UnicodeString

Event ID 32849: Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Send(Async)

Description

Runspace Id: Runspace_Id Pipeline Id: Pipeline_Id. Server is sending data of size TargetInterface to client. DataType: Runspace_InstanceId TargetInterface: PowerShell_InstanceId.

Message #

Runspace Id: %1 Pipeline Id: %2. Server is sending data of size %3 to client. DataType: %4 TargetInterface: %5

Fields #

NameDescription
Runspace_InstanceId UnicodeString
PowerShell_InstanceId UnicodeString
DataSize UnicodeString
DataType UInt32
Known values
65538
SESSION_CAPABILITY (0x00010002) - Session capability; bidirectional
65540
INIT_RUNSPACEPOOL (0x00010004) - Initialize RunspacePool; client to server
65541
PUBLIC_KEY (0x00010005) - Public key; client to server
65542
ENCRYPTED_SESSION_KEY (0x00010006) - Encrypted session key; server to client
65543
PUBLIC_KEY_REQUEST (0x00010007) - Public key request; server to client
65544
CONNECT_RUNSPACEPOOL (0x00010008) - Connect to a RunspacePool; client to server
135170
SET_MAX_RUNSPACES (0x00021002) - Set maximum runspaces; client to server
135171
SET_MIN_RUNSPACES (0x00021003) - Set minimum runspaces; client to server
135172
RUNSPACE_AVAILABILITY (0x00021004) - Runspace availability response; server to client
135173
RUNSPACEPOOL_STATE (0x00021005) - RunspacePool state info; server to client
135174
CREATE_PIPELINE (0x00021006) - Create and invoke pipeline; client to server
135175
GET_AVAILABLE_RUNSPACES (0x00021007) - Get available runspace count; client to server
135176
USER_EVENT (0x00021008) - User-defined event; server to client
135177
APPLICATION_PRIVATE_DATA (0x00021009) - Application private data; server to client
135178
GET_COMMAND_METADATA (0x0002100A) - Get command metadata; client to server
135179
RUNSPACEPOOL_INIT_DATA (0x0002100B) - RunspacePool initialization data; server to client
135180
RESET_RUNSPACE_STATE (0x0002100C) - Reset RunspacePool runspace state; client to server
135424
RUNSPACEPOOL_HOST_CALL (0x00021100) - Host method call on RunspacePool; server to client
135425
RUNSPACEPOOL_HOST_RESPONSE (0x00021101) - Host call response for RunspacePool; client to server
266242
PIPELINE_INPUT (0x00041002) - Pipeline input; client to server
266243
END_OF_PIPELINE_INPUT (0x00041003) - Close pipeline input collection; client to server
266244
PIPELINE_OUTPUT (0x00041004) - Pipeline output; server to client
266245
ERROR_RECORD (0x00041005) - Pipeline error record; server to client
266246
PIPELINE_STATE (0x00041006) - Pipeline state info; server to client or RunspacePool
266247
DEBUG_RECORD (0x00041007) - Pipeline debug record; server to client
266248
VERBOSE_RECORD (0x00041008) - Pipeline verbose record; server to client
266249
WARNING_RECORD (0x00041009) - Pipeline warning record; server to client
266256
PROGRESS_RECORD (0x00041010) - Pipeline progress record; server to client
266257
INFORMATION_RECORD (0x00041011) - Pipeline information record; server to client
266496
PIPELINE_HOST_CALL (0x00041100) - Host method call on pipeline; server to client
266497
PIPELINE_HOST_RESPONSE (0x00041101) - Host call response for pipeline; client to server
TargetInterface UInt323 to client. DataType.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32849,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 21,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.022+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0000-F6D5-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 15220,
      "thread_id": 4892
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DataSize": "223",
    "DataType": 65538,
    "PowerShell_InstanceId": "00000000-0000-0000-0000-000000000000",
    "Runspace_InstanceId": "00000000-0000-0000-0000-000000000000",
    "TargetInterface": 1
  },
  "message": "win:None"
}

Event ID 32850: Request param1.

#
Channel
Analytic
Task
win:None
Opcode
connect

Description

Request param1. Creating a server remote session. UserName: UserName Custome Shell Id: CustomeShellId.

Message #

Request %1. Creating a server remote session. UserName: %2 Custome Shell Id: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32851: Reporting context for request: ReportingContextForRequest Context Reported: ReportingContextForRequest.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
connect

Message #

Reporting context for request: %1 Context Reported: %1

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32851,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 12,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T05:29:54.158+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0001-EB9A-828753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 19268
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "System.Management.Automation.Remoting.Client.WSManNativeApi+WSManPluginRequest",
    "param2": "System.Management.Automation.Remoting.Client.WSManNativeApi+WSManPluginRequest"
  },
  "message": "win:None"
}

Event ID 32852: Reporting operation complete for request: ReportingOperationCompleteForRequest.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
connect

Message #

Reporting operation complete for request: %1 
 Error Code: %2 
 Error Message: %3 
 StackTrace: %4

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32852,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 11,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T05:29:54.150+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0008-D88F-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 10052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "System.Management.Automation.Remoting.Client.WSManNativeApi+WSManPluginRequest",
    "param2": "NoError",
    "param3": "",
    "param4": ""
  },
  "message": "win:None"
}

Event ID 32853: Shell Context param1.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
connect

Description

Shell Context param1. Request Id param2. Creating a commonad session for running a command.

Message #

Shell Context %1. Request Id %2. Creating a commonad session for running a command.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32853,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 12,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T05:29:54.150+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0008-D88F-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 10052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "",
    "param2": "CreateCommand: Create a new command in the shell context completed"
  },
  "message": "win:None"
}

Event ID 32854: Shell Context param1 Command Context param2 Request Id param3.

#
Channel
Analytic
Task
win:None
Opcode
Disconnect

Description

Shell Context param1 Command Context param2 Request Id param3. Stopping command.

Message #

Shell Context %1 Command Context %2 Request Id %3. Stopping command.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32855: Shell Context param1 Command Context param2 Request Id param3.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Open(async)

Description

Shell Context param1 Command Context param2 Request Id param3. Received data from client.

Message #

Shell Context %1 Command Context %2 Request Id %3. Received data from client.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32855,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 10,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T05:29:54.161+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0008-D88F-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 10052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "",
    "param2": "PerformWSManPluginReceive: Invoked",
    "param3": ""
  },
  "message": "win:None"
}

Event ID 32856: Shell Context param1 Command Context param2 Request Id param3.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
win:None
Opcode
Open(async)

Description

Shell Context param1 Command Context param2 Request Id param3. Client sent a receive request so that server can send data.

Message #

Shell Context %1 Command Context %2 Request Id %3. Client sent a receive request so that server can send data.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32856,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 10,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T05:29:54.161+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0008-D88F-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 10052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "",
    "param2": "EnableShellOrCommandToSendDataToClient: unlock the shell / command specified so that the shell / command starts sending data to the client.",
    "param3": ""
  },
  "message": "win:None"
}

Event ID 32857: Shell Context param1 Command Context param2 IsReceiveOperation param3.

#
Channel
Analytic
Task
win:None
Opcode
Disconnect

Description

Shell Context param1 Command Context param2 IsReceiveOperation param3. Got close operation request.

Message #

Shell Context %1 Command Context %2 IsReceiveOperation %3. Got close operation request.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32865: Loading assembly param1 for custom shell with shell Id param2.

#
Channel
Analytic
Task
win:None
Opcode
connect

Message #

Loading assembly %1 for custom shell with shell Id %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 32866: Loading type param1 for custom shell with shell Id param2.

#
Channel
Analytic
Task
win:None
Opcode
connect

Message #

Loading type %1 for custom shell with shell Id %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 32867: Received remoting fragment.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
win:None
Opcode
Receive(Async)

Message #

Received remoting fragment. 
 	 Object Id: %1 
 	 Fragment Id: %2 
 	 Start Flag: %3 
 	 End Flag: %4 
 	 Payload Length: %5 
 	 Payload Data: %6

Fields #

NameDescription
ObjectId Int64
FragmentId Int64
sFlag Int32
Known values
0
Not a Start fragment - this fragment is a continuation of a previous fragment
1
Start fragment - this is the first fragment of a PSRP message (FragmentId must be 0)
eFlag Int32
Known values
0
Not an End fragment - more fragments follow for this PSRP message
1
End fragment - this is the final fragment of a PSRP message
FragmentLength UInt32
FragmentPayload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32867,
    "version": 1,
    "level": 5,
    "task": 0,
    "opcode": 22,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:47.999+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0000-F6D5-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 15220,
      "thread_id": 4892
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FragmentId": 0,
    "FragmentLength": 752,
    "FragmentPayload": "0x0200000002000100F80C45E3FDEBC74497D8B6C7C3DA856900000000000000000000000000000000EFBBBF3C4F626A2052656649643D2230223E3C4D533E3C56657273696F6E204E3D2270726F746F636F6C76657273696F6E223E322E333C2F56657273696F6E3E3C56657273696F6E204E3D22505356657273696F6E223E322E303C2F56657273696F6E3E3C56657273696F6E204E3D2253657269616C697A6174696F6E56657273696F6E223E312E312E302E313C2F56657273696F6E3E3C4241204E3D2254696D655A6F6E65223E414145414141442F2F2F2F2F415141414141414141414145415141414142785465584E305A57307551335679636D567564464E356333526C62565270625756616232356C424141414142647458304E685932686C5A455268655778705A32683051326868626D646C63773174583352705932747A54325A6D63325630446D316663335268626D5268636D524F5957316C446D31665A47463562476C6E6148524F5957316C417741424152785465584E305A573075513239736247566A64476C76626E4D755347467A61485268596D786C43516B434141414141414141414141414141414B436751434141414148464E356333526C62533544623278735A574E30615739756379354959584E6F644746696247554841414141436B78765957524759574E3062334948566D567963326C76626768446232317759584A6C6368424959584E6F5132396B5A56427962335A705A47567943456868633268546158706C4245746C65584D47566D46736457567A41414144417741464251734948464E356333526C62533544623278735A574E30615739756379354A51323974634746795A58496B55336C7A644756744C6B4E766247786C593352706232357A4C6B6C4959584E6F5132396B5A56427962335A705A475679434F78524F4438414141414143676F444141414143514D414141414A424141414142414441414141414141414142414541414141414141414141733D3C2F42413E3C2F4D533E3C2F4F626A3E",
    "ObjectId": 17,
    "eFlag": 1,
    "sFlag": 1
  },
  "message": "win:None"
}

Event ID 32868: Sent remoting fragment.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
win:None
Opcode
Send(Async)

Message #

Sent remoting fragment. 
 	 Object Id: %1 
 	 Fragment Id: %2 
 	 Start Flag: %3 
 	 End Flag: %4 
 	 Payload Length: %5 
 	 Payload Data: %6

Fields #

NameDescription
ObjectId Int64
FragmentId Int64
sFlag Int32
Known values
0
Not a Start fragment - this fragment is a continuation of a previous fragment
1
Start fragment - this is the first fragment of a PSRP message (FragmentId must be 0)
eFlag Int32
Known values
0
Not an End fragment - more fragments follow for this PSRP message
1
End fragment - this is the final fragment of a PSRP message
FragmentLength UInt32
FragmentPayload UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 32868,
    "version": 1,
    "level": 5,
    "task": 0,
    "opcode": 21,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T04:29:48.022+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0000-F6D5-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 15220,
      "thread_id": 4892
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FragmentId": 0,
    "FragmentLength": 202,
    "FragmentPayload": "0x01000000020001000000000000000000000000000000000000000000000000000000000000000000EFBBBF3C4F626A2052656649643D2230223E3C4D533E3C56657273696F6E204E3D2270726F746F636F6C76657273696F6E223E322E333C2F56657273696F6E3E3C56657273696F6E204E3D22505356657273696F6E223E322E303C2F56657273696F6E3E3C56657273696F6E204E3D2253657269616C697A6174696F6E56657273696F6E223E312E312E302E313C2F56657273696F6E3E3C2F4D533E3C2F4F626A3E",
    "ObjectId": 1,
    "eFlag": 1,
    "sFlag": 1
  },
  "message": "win:None"
}

Event ID 32869: Shutting down winrm service.

#
Channel
Analytic
Task
win:None
Opcode
Shuttingdown

Event ID 40961: PowerShell console is starting up

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellConsoleStartup
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 40961,
    "version": 1,
    "level": 4,
    "task": 4,
    "opcode": 1,
    "keywords": 0,
    "time_created": "2026-06-13T05:24:19.4248057+00:00",
    "event_record_id": 164809,
    "correlation": {
      "ActivityID": "{AA583517-FAF4-0001-143A-58AAF4FADC01}"
    },
    "execution": {
      "process_id": 7180,
      "thread_id": 7184
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": "PowerShell console is starting up"
}

Event ID 40962: PowerShell console is ready for user input

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellConsoleStartup
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 40962,
    "version": 1,
    "level": 4,
    "task": 4,
    "opcode": 2,
    "keywords": 0,
    "time_created": "2026-06-13T05:24:20.0746353+00:00",
    "event_record_id": 164811,
    "correlation": {
      "ActivityID": "{AA583517-FAF4-0001-143A-58AAF4FADC01}"
    },
    "execution": {
      "process_id": 7180,
      "thread_id": 7184
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": "PowerShell console is ready for user input"
}

Event ID 45057: Tracing ErrorRecord.

#
Channel
Debug
Opcode
Tobeusedwhenanexceptionisraised

Message #

Tracing ErrorRecord: 
 Message: %1 
 CategoryInfo.Category: %2 
 CategoryInfo.Reason : %3 
 CategoryInfo.TargetName : %4 
 FullyQualifiedErrorId: %5 
 Exception Details: 
 Message : %6 
 Stack Trace: %7 
 InnerException %8

Fields #

NameDescription
Message UnicodeString[Exception Details] Message.
Category UnicodeString
Reason UnicodeString
TargetName UnicodeString
FullyQualifiedErrorId UnicodeString[Tracing ErrorRecord] FullyQualifiedErrorId.
ExceptionMessage UnicodeString
ExceptionStackTrace UnicodeString
ExceptionInnerException UnicodeString

Event ID 45058: Exception: Message: Message StackTrace: StackTrace InnerException : InnerException.

#
Channel
Debug
Opcode
Tobeusedwhenanexceptionisraised

Description

Exception.

Message #

Exception: 
 Message: %1 
 StackTrace: %2 
 InnerException : %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 45059: Tracing PSObject

#
Channel
Debug
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Event ID 45060: Tracing Job: Id: Id InstanceId: InstanceId Name: Name Location: Location State: State Command: Command.

#
Channel
Debug
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Tracing Job.

Message #

Tracing Job: 
 Id: %1 
 InstanceId: %2 
 Name: %3 
 Location: %4 
 State: %5 
 Command: %6

Fields #

NameDescription
Id UnicodeString[Tracing Job] Id.
InstanceId UnicodeString[Tracing Job] InstanceId.
Name UnicodeString[Tracing Job] Name.
Location UnicodeString[Tracing Job] Location.
State UnicodeString[Tracing Job] State.
Command UnicodeString[Tracing Job] Command.

Event ID 45061: Trace Information.

#
Channel
Debug
Also via
realtime ETW trace
Level
Informational

Message #

Trace Information: 
 %1

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 45061,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x2000000000000000",
    "time_created": "2026-06-02T04:29:47.998+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0000-F6D5-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 15220,
      "thread_id": 4892
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "OutOfProcessUtils.ProcessElement : PS_OUT_OF_PROC_DATA received, psGuid : 00000000-0000-0000-0000-000000000000"
  },
  "message": "win:None"
}

Event ID 45062: Connection Paramters are Connection URI: Connection_URI Resource URI: Resource_URI User: User OpenTimeout: OpenTimeout IdleTimeout: IdleTimeout CancelTimeout: CancelTimeout AuthenticationMechanism:...

#
Channel
Debug
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Description

Connection Paramters are.

Message #

Connection Paramters are 
 Connection URI: %1 
 Resource URI: %2 
 User: %3 
 OpenTimeout: %4 
 IdleTimeout: %5 
 CancelTimeout: %6 
 AuthenticationMechanism: %7 
 Thumb Print: %8 
 MaxUriRedirectionCount: %9 
 MaxReceivedDataSizePerCommand: %10 
 MaxReceivedObjectSize: %11

Fields #

NameDescription
uri UnicodeString
shell UnicodeString
userName UnicodeString
opentimeout UnicodeString
idletimeout UnicodeString
canceltimeout UnicodeString
auth UInt32
Known values
0
Default - use the default authentication defined by the underlying protocol
1
Basic - use Basic authentication (credentials sent in clear text)
2
Negotiate - use Negotiate authentication for the remote connection
3
NegotiateWithImplicitCredential - use Negotiate with implicit credentials
4
CredSSP - use Credential Security Support Provider authentication
5
Digest - use Digest authentication (credentials sent as a hash value)
6
Kerberos - use Kerberos mutual authentication with certificates
thumbPrint UnicodeString
redircount UnicodeString
recvdDataSize UnicodeString
recvdObjSize UnicodeString

Event ID 45063: Workflow plugin loaded.

#
Channel
Analytic
Task
WorkflowHosting
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow plugin loaded. 
 	 EndpointName: %1 
 	 User: %2 
 	 HostingMode: %3 
 	 Protocol: %4 
 	 Configuration: 
 %5

Fields #

NameDescription
endpointName UnicodeString
user UnicodeString
hostingMode UnicodeString
protocol UnicodeString
configuration UnicodeString

Event ID 45064: Workflow execution started.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow execution started. 
 	 WorkflowId: %1 
 	 ManagedNodes: %2

Fields #

NameDescription
workflowId GUID
managedNodes UnicodeString

Event ID 45065: Workflow state changed.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow state changed. 
 	 WorkflowId: %1 
 	 NewState: %2 
 	 OldState: %3

Fields #

NameDescription
workflowId GUID
newState UnicodeString
oldState UnicodeString

Event ID 45072: Workflow plugin has been requested for a shutdown.

#
Channel
Analytic
Task
WorkflowHosting
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow plugin has been requested for a shutdown. 
 	 EndpointName: %1

Fields #

NameDescription
endpointName UnicodeString

Event ID 45073: Workflow plugin restarted.

#
Channel
Analytic
Task
WorkflowHosting
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow plugin restarted. 
 	 EndpointName: %1

Fields #

NameDescription
endpointName UnicodeString

Event ID 45074: Workflow is resuming.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow is resuming. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45075: A quota limit that was set for the endpoint was exceeded.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

A quota limit that was set for the endpoint was exceeded. 
 	 EndpointName: %1 
 	 ConfigName: %2 
 	 AllowedValue: %3 
 	 ValueInQuestion: %4

Fields #

NameDescription
endpointName UnicodeString
configName UnicodeString
allowedValue UnicodeString
valueInQuestion UnicodeString

Event ID 45076: Workflow has resumed.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow has resumed. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45078: Workflow runspace pool was created.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow runspace pool was created. 
 	 WorkflowId: %1 
 	 ManagedNode: %2

Fields #

NameDescription
workflowId GUID
managedNode UnicodeString

Event ID 45079: Activity was queued for execution.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Activity was queued for execution. 
 	 WorkflowId: %1 
 	 ActivityName: %2

Fields #

NameDescription
workflowId GUID
activityName UnicodeString

Event ID 45080: Activity execution started.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Activity execution started. 
 	 ActivityName: %1 
 	 ActivityTypeName: %2

Fields #

NameDescription
activityName UnicodeString
activityTypeName UnicodeString

Event ID 45081: Workflow is being imported from a XAML file.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow is being imported from a XAML file. 
 	 WorkflowId: %1 
 	 XamlFile: %2

Fields #

NameDescription
workflowId GUID
xamlFile UnicodeString

Event ID 45082: Workflow has been imported from a XAML file.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow has been imported from a XAML file. 
 	 WorkflowId: %1 
 	 XamlFile: %2

Fields #

NameDescription
workflowId GUID
xamlFile UnicodeString

Event ID 45083: Workflow could not be imported from a XAML file because of an error.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow could not be imported from a XAML file because of an error. 
 	 WorkflowId: %1 
 	 ErrorDescription: %2

Fields #

NameDescription
workflowId GUID
errorDescription UnicodeString

Event ID 45084: Workflow validation started.

#
Channel
Analytic
Task
WorkflowValidation
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow validation started. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45085: Workflow validation succeeded.

#
Channel
Analytic
Task
WorkflowValidation
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow validation succeeded. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45086: Workflow validation failed with error.

#
Channel
Analytic
Task
WorkflowValidation
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow validation failed with error. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45087: Workflow activity validated.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow activity validated. 
 	 WorkflowId: %1 
 	 ActivityDisplayName: %2 
 	 ActivityTypeName: %3

Fields #

NameDescription
workflowId GUID
activityDisplayName UnicodeString
activityType UnicodeString

Event ID 45088: Workflow activity could not be validated.

#
Channel
Analytic
Task
WorkflowValidation
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow activity could not be validated. 
 	 WorkflowId: %1 
 	 ActivityDisplayName: %2 
 	 ActivityTypeName: %3

Fields #

NameDescription
workflowId GUID
activityDisplayName UnicodeString
activityType UnicodeString

Event ID 45089: Activity execution failed.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Activity execution failed. 
 	 WorkflowId: %1 
 	 ActivityName: %2 
 	 FailureDescription: %3

Fields #

NameDescription
workflowId GUID
activityName UnicodeString
failureDescription UnicodeString

Event ID 45090: Runspace availability changed.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Runspace availability changed. 
 	 RunspaceId: %1 
 	 Availability: %2

Fields #

NameDescription
runspaceId UnicodeString
availability UnicodeString

Event ID 45091: Runspace state changed.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Runspace state changed. 
 	 RunspaceId: %1 
 	 NewState: %2 
 	 OldState: %3

Fields #

NameDescription
runspaceId UnicodeString
newState UnicodeString
oldState UnicodeString

Event ID 45092: Workflow loaded for execution.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow loaded for execution. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45093: Workflow unloaded.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow unloaded. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45094: Workflow execution cancelled.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow execution cancelled. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45095: Workflow execution aborted.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow execution aborted. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45096: Workflow cleanup operation executed.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow cleanup operation executed. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45097: Persisted workflow loaded from disk.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Persisted workflow loaded from disk. 
 	 WorkflowId: %1 
 	 Path: %2

Fields #

NameDescription
workflowId GUID
path UnicodeString

Event ID 45098: Workflow data was deleted from disk.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow data was deleted from disk. 
 	 WorkflowId: %1 
 	 Path: %2

Fields #

NameDescription
workflowId GUID
path UnicodeString

Event ID 45100: Starting remove job.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Starting remove job. 
 	 JobId: %1

Fields #

NameDescription
jobId GUID

Event ID 45101: Job state changed.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Job state changed. 
 	 JobId: %1 
 	 WorkflowId: %2 
 	 NewState: %3 
 	 OldState: %4

Fields #

NameDescription
jobId Int32
workflowId GUID
newState UnicodeString
oldState UnicodeString

Event ID 45102: Job error.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Job error. 
 	 JobId: %1 
 	 WorkflowId: %2 
 	 ErrorDescription: %3

Fields #

NameDescription
jobId Int32
workflowId GUID
errorDescription UnicodeString

Event ID 45104: Job created for workflow (child job).

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Job created for workflow (child job). 
 	 ParentJobId: %1 
 	 ChildJobId: %2 
 	 ChildWorkflowId: %3

Fields #

NameDescription
parentJobId GUID
childJobId GUID
childWorkflowId GUID

Event ID 45105: Parent job created for workflow.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Parent job created for workflow. 
 	 JobId: %1

Fields #

NameDescription
jobId GUID

Event ID 45106: All required jobs were created for workflow execution.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

All required jobs were created for workflow execution. 
 	 JobId: %1 
 	 WorkflowId: %2

Fields #

NameDescription
jobId GUID
workflowId GUID

Event ID 45107: Child job removed for workflow.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Child job removed for workflow. 
 	 ParentJobId: %1 
 	 ChildJobId: %2 
 	 WorkflowId: %3

Fields #

NameDescription
parentJobId GUID
childJobId GUID
workflowId GUID

Event ID 45108: An error occurred while removing job.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

An error occurred while removing job. 
 	 ParentJobId: %1 
 	 ChildJobId: %2 
 	 WorkflowId: %3 
 	 Error: %4

Fields #

NameDescription
parentJobId GUID
childJobId GUID
workflowId GUID
error UnicodeString

Event ID 45109: Loading workflow for execution.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Loading workflow for execution. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45110: Workflow execution finished.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow execution finished. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45111: Cancelling workflow execution.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Cancelling workflow execution. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45112: Aborting workflow execution.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Aborting workflow execution. 
 	 WorkflowId: %1 
 	 Reason: %2

Fields #

NameDescription
workflowId GUID
reason UnicodeString

Event ID 45113: Unloading workflow.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Unloading workflow. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45114: Forced workflow shutdown started.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Forced workflow shutdown started. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45115: Forced workflow shutdown finished.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Forced workflow shutdown finished. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45116: An error occurred while forcefully shutting down a workflow.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

An error occurred while forcefully shutting down a workflow. 
 	 WorkflowId: %1 
 	 ErrorDescription: %2

Fields #

NameDescription
workflowId GUID
errorDescription UnicodeString

Event ID 45117: Persisting workflow to disk.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Persisting workflow to disk. 
 	 WorkflowId: %1 
 	 PersistPath: %2

Fields #

NameDescription
workflowId GUID
persistPath UnicodeString

Event ID 45118: Workflow persisted to disk.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow persisted to disk. 
 	 WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45119: Activity execution finished.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Activity execution finished. 
 	 ActivityName: %1

Fields #

NameDescription
activityName UnicodeString

Event ID 45120: Workflow execution error.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow execution error. 
 	 WorkflowId: %1 
 	 ErrorDescription: %2

Fields #

NameDescription
workflowId GUID
errorDescription UnicodeString

Event ID 45121: A new PowerShell endpoint was registered.

#
Channel
Analytic
Task
Configuration
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

A new PowerShell endpoint was registered. 
 	 EndpointName: %1 
 	 EndpointType: %2 
 	 RegisteredBy: %3

Fields #

NameDescription
endpointName UnicodeString
endpointType UnicodeString
registeredBy UnicodeString

Event ID 45122: Endpoint configuration modified.

#
Channel
Analytic
Task
Configuration
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Endpoint configuration modified. 
 	 EndpointName: %1 
 	 ModifiedBy: %2

Fields #

NameDescription
endpointName UnicodeString
modifiedBy UnicodeString

Event ID 45123: Endpoint configuration unregistered.

#
Channel
Analytic
Task
Configuration
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Endpoint configuration unregistered. 
 	 EndpointName: %1 
 	 UnregisteredBy: %2

Fields #

NameDescription
endpointName UnicodeString
unregisteredBy UnicodeString

Event ID 45124: Endpoint configuration disabled.

#
Channel
Analytic
Task
Configuration
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Endpoint configuration disabled. 
 	 EndpointName: %1 
 	 DisabledBy: %2

Fields #

NameDescription
endpointName UnicodeString
disabledBy UnicodeString

Event ID 45125: Endpoint configuration enabled.

#
Channel
Analytic
Task
Configuration
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Endpoint configuration enabled. 
 	 EndpointName: %1 
 	 EnabledBy: %2

Fields #

NameDescription
endpointName UnicodeString
enabledBy UnicodeString

Event ID 45126: Out of process runspace started.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Out of process runspace started. 
 	 Command: %1

Fields #

NameDescription
command UnicodeString

Event ID 45127: Parameter splatting was performed during workflow execution.

#
Channel
Analytic
Task
WorkflowExecution
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Parameter splatting was performed during workflow execution. 
 	 Parameters: %1 
 	 Computers: %2

Fields #

NameDescription
parameters UnicodeString
computers UnicodeString

Event ID 45128: Workflow engine started.

#
Channel
Analytic
Task
WorkflowHosting
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Workflow engine started. 
 	 EndpointName: %1

Fields #

NameDescription
endpointName UnicodeString

Event ID 45129: Workflow manager instantiated with CheckpointPath: CheckpointPath ConfigProviderId: ConfigProviderId UserName: UserName Path: Path.

#
Channel
Debug

Description

Workflow manager instantiated with.

Message #

Workflow manager instantiated with 
 	 CheckpointPath: %1 
 	 ConfigProviderId: %2 
 	 UserName: %3 
 	 Path: %4

Fields #

NameDescription
checkpointPath UnicodeString
configProviderId UnicodeString
userName UnicodeString
path UnicodeString

Event ID 46337: BEGIN ImportWorkflowCommand::StartWorkflowApplication.

#
Channel
Debug

Description

BEGIN ImportWorkflowCommand::StartWorkflowApplication. Starting invocation of workflow function. Tracking Guid TrackingId.

Message #

BEGIN ImportWorkflowCommand::StartWorkflowApplication. Starting invocation of workflow function. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46338: END ImportWorkflowCommand::StartWorkflowApplication.

#
Channel
Debug

Description

END ImportWorkflowCommand::StartWorkflowApplication. Ending invocation of workflow function. Tracking Guid TrackingId.

Message #

END ImportWorkflowCommand::StartWorkflowApplication. Ending invocation of workflow function. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46339: BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication.

#
Channel
Debug

Description

BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid TrackingId.

Message #

BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46340: END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.

#
Channel
Debug

Description

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid TrackingId.

Message #

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46341: END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.

#
Channel
Debug

Description

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid TrackingId : ContainerParentJob Guid ContainerParentJobInstanceId.

Message #

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1 : ContainerParentJob Guid %2

Fields #

NameDescription
TrackingId GUID
ContainerParentJobInstanceId GUID

Event ID 46342: BEGIN JobLogic ContainerParentJob Guid WorkflowJobJobInstanceId.

#
Channel
Debug

Message #

BEGIN JobLogic ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46343: END JobLogic ContainerParentJob Guid WorkflowJobJobInstanceId.

#
Channel
Debug

Message #

END JobLogic ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46344: BEGIN WorkflowExecution ContainerParentJob Guid WorkflowJobJobInstanceId.

#
Channel
Debug

Message #

BEGIN WorkflowExecution ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46345: END WorkflowExecution ContainerParentJob Guid WorkflowJobJobInstanceId.

#
Channel
Debug

Message #

END WorkflowExecution ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46346: WorkflowJob with Guid WorkflowJobInstanceId added to ContainerParentJob with Guid ContainerParentJobInstanceId.

#
Channel
Debug

Message #

WorkflowJob with Guid %1 added to ContainerParentJob with Guid %2

Fields #

NameDescription
WorkflowJobInstanceId GUID
ContainerParentJobInstanceId GUID

Event ID 46347: ProxyJob with Guid ProxyJobInstanceId associated with remote ContainerParentJob with Guid ContainerParentJobInstanceId.

#
Channel
Debug

Message #

ProxyJob with Guid %1 associated with remote ContainerParentJob with Guid %2

Fields #

NameDescription
ProxyJobInstanceId GUID
ContainerParentJobInstanceId GUID

Event ID 46348: BEGIN Execution of ContainerParentJob with Guid ContainerParentJobInstanceId.

#
Channel
Debug

Message #

BEGIN Execution of ContainerParentJob with Guid %1

Fields #

NameDescription
ContainerParentJobInstanceId GUID

Event ID 46349: END Execution of ContainerParentJob with Guid ContainerParentJobInstanceId.

#
Channel
Debug

Message #

END Execution of ContainerParentJob with Guid %1

Fields #

NameDescription
ContainerParentJobInstanceId GUID

Event ID 46350: BEGIN Execution of Proxy Job with Guid ProxyJobInstanceId.

#
Channel
Debug

Message #

BEGIN Execution of Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46351: END Execution of Proxy Job with Guid ProxyJobInstanceId.

#
Channel
Debug

Message #

END Execution of Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46352: BEGIN StateChanged event handler for Proxy Job with Guid ProxyJobInstanceId.

#
Channel
Debug

Message #

BEGIN StateChanged event handler for Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46353: END StateChanged event handler for Proxy Job with Guid ProxyJobInstanceId.

#
Channel
Debug

Message #

END StateChanged event handler for Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46354: BEGIN StateChanged event handler for Proxy Child Job with Guid ProxyChildJobInstanceId.

#
Channel
Debug

Message #

BEGIN StateChanged event handler for Proxy Child Job with Guid %1

Fields #

NameDescription
ProxyChildJobInstanceId GUID

Event ID 46355: END StateChanged event handler for Proxy Child Job with Guid ProxyChildJobInstanceId.

#
Channel
Debug

Message #

END StateChanged event handler for Proxy Child Job with Guid %1

Fields #

NameDescription
ProxyChildJobInstanceId GUID

Event ID 46356: BEGIN Running garbage collection

#
Channel
Debug

Event ID 46357: END Running garbage collection

#
Channel
Debug

Event ID 46358: Persistence store has reached its maximum specified size

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Event ID 49152: message.

#
Channel
Debug

Message #

%1

Fields #

NameDescription
message UnicodeString

Event ID 49153: Trace Information.

#
Channel
Debug

Message #

Trace Information: 
 %1 %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 53249: Scheduled Job ScheduledJobDefName started at StartTime.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellScheduledJobs
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Scheduled Job %1 started at %2

Fields #

NameDescription
ScheduledJobDefName UnicodeString
StartTime UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 53249,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 8576,
      "thread_id": 13760
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 20,
    "provider": "Microsoft-Windows-PowerShell",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:33.435Z",
    "version": 0
  },
  "event_data": {
    "ScheduledJobDefName": "dwh_psjob",
    "StartTime": "7/22/2026 5:46:32 AM"
  },
  "message": ""
}

Event ID 53250: Scheduled Job ScheduledJobDefName completed at StopTime with state State.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellScheduledJobs
Opcode
Tobeusedwhenoperationisjustexecutingamethod

Message #

Scheduled Job %1 completed at %2 with state %3

Fields #

NameDescription
ScheduledJobDefName UnicodeString
StopTime UnicodeString
State UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 53250,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 8576,
      "thread_id": 13760
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 20,
    "provider": "Microsoft-Windows-PowerShell",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:33.749Z",
    "version": 0
  },
  "event_data": {
    "ScheduledJobDefName": "dwh_psjob",
    "State": "Completed",
    "StopTime": "7/22/2026 5:46:33 AM"
  },
  "message": ""
}

Event ID 53251: Scheduled Job Exception Message.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellScheduledJobs
Opcode
Tobeusedwhenanexceptionisraised

Message #

Scheduled Job Exception %1: 
 Message: %2 
 StackTrace: %3 
 InnerException: %4

Fields #

NameDescription
Name UnicodeString
Message UnicodeString
StackTrace UnicodeString
InnerException UnicodeString

Event ID 53504: Windows PowerShell has started an IPC listening thread on process: param1 in AppDomain: param2.

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellNamedPipeIPC
Opcode
Open(async)

Message #

Windows PowerShell has started an IPC listening thread on process: %1 in AppDomain: %2.

Fields #

NameDescription
param1 UnicodeStringWindows PowerShell has started an IPC listening thread on process.
param2 UnicodeStringin AppDomain.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PowerShell",
    "guid": "{A0C1853B-5C40-4B15-8766-3CF1C58F985A}",
    "event_source_name": "",
    "event_id": 53504,
    "version": 1,
    "level": 4,
    "task": 111,
    "opcode": 10,
    "keywords": 0,
    "time_created": "2026-06-13T14:08:49.4178649+00:00",
    "event_record_id": 168240,
    "correlation": {
      "ActivityID": "{DFAAFF10-0837-4168-B0A2-798638094318}"
    },
    "execution": {
      "process_id": 7864,
      "thread_id": 7432
    },
    "channel": "Microsoft-Windows-PowerShell/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "7864",
    "param2": "DefaultAppDomain"
  },
  "message": "Windows PowerShell has started an IPC listening thread on process: 7864 in AppDomain: DefaultAppDomain."
}

Event ID 53505: Windows PowerShell has ended an IPC listening thread on process: param1 in AppDomain: param2.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellNamedPipeIPC
Opcode
Close(Async)

Message #

Windows PowerShell has ended an IPC listening thread on process: %1 in AppDomain: %2.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 53506: An error has occurred in Windows PowerShell IPC listening thread on process: param1 in AppDomain: param2.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellNamedPipeIPC
Opcode
Tobeusedwhenanexceptionisraised

Description

An error has occurred in Windows PowerShell IPC listening thread on process: param1 in AppDomain: param2. Error Message: ErrorMessage.

Message #

An error has occurred in Windows PowerShell IPC listening thread on process: %1 in AppDomain: %2.  Error Message: %3.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 53507: Windows PowerShell IPC connect on process: param1 in AppDomain: param2 for User: param3.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellNamedPipeIPC
Opcode
connect

Message #

Windows PowerShell IPC connect on process: %1 in AppDomain: %2 for User: %3.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 53508: Windows PowerShell IPC disconnect on process: param1 in AppDomain: param2 for User: param3.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
PowerShellNamedPipeIPC
Opcode
Close(Async)

Message #

Windows PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Provenance

ETW provider GUID {A0C1853B-5C40-4B15-8766-3CF1C58F985A}

Defined in PSEvents.dll, which carries the event manifest.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • JD-WIN11-22H2-1-native-20260719, sample captured from a live trace, binary version 10.0.22621.3672, captured 2026-07-19

    Native ETL capture of PowerShell runspace, serialization, error, and localhost remoting activity; identifiers were sanitized in catalog examples.