PowerShellCore
191 events across 4 channels
Event ID 4100: NoneTobeusedwhenanexceptionisraised_V1
#Event ID 4101: NoneTobeusedwhenanexceptionisraised4101_V1
#Event ID 4102: NoneTobeusedwhenanexceptionisraised4102_V1
#Event ID 4103: NoneTobeusedwhenanexceptionisraised4103_V1
#Event ID 4104: Creating Scriptblock text (1 of 1): $global:?
#Message #
Fields #
| Name | Description |
|---|---|
MessageNumber | |
MessageTotal | |
ScriptBlockText | |
ScriptBlockId | |
Path |
Example Event #
{
"system": {
"provider": "PowerShellCore",
"guid": "{F90714A8-5509-434A-BF6D-B1624C8A19A2}",
"event_source_name": "",
"event_id": 4104,
"version": 1,
"level": 5,
"task": 2,
"opcode": 15,
"keywords": 0,
"time_created": "2026-05-30T04:29:54.7799039+00:00",
"event_record_id": 30,
"correlation": {
"ActivityID": "{14429F51-EFE2-000D-01E6-4214E2EFDC01}"
},
"execution": {
"process_id": 11980,
"thread_id": 5976
},
"channel": "PowerShellCore/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"MessageNumber": "1",
"MessageTotal": "1",
"ScriptBlockText": "$global:?",
"ScriptBlockId": "e76104e3-fb87-4091-ba9e-8ae27765de3e",
"Path": ""
},
"message": "Creating Scriptblock text (1 of 1):\r\n$global:?\r\n\r\nScriptBlock ID: e76104e3-fb87-4091-ba9e-8ae27765de3e\r\nPath: "
}
Event ID 4105: StartingCommandOpen
#Event ID 4106: StoppingCommandClose
#Event ID 7937: NoneTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 7938: NoneTobeusedwhenoperationisjustexecutingamethod7938_V1
#Event ID 7939: NoneTobeusedwhenoperationisjustexecutingamethod7939_V1
#Event ID 7940: NoneTobeusedwhenoperationisjustexecutingamethod7940_V1
#Event ID 7941: task_0Tobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 7942: NoneTobeusedwhenoperationisjustexecutingamethod7942_V1
#Event ID 8193: ConnectOBEUSEDWHENANOBJECTISCONSTRUCTEDobeusedwhenanobjectisconstructed_V1
#Event ID 8194: ConnectOBEUSEDWHENANOBJECTISCONSTRUCTEDobeusedwhenanobjectisconstructed8194_V1
#Event ID 8198: ConnectOpen
#Event ID 12033: ConnectTobeusedwhenoperationisjustexecutingamethod12033_V1
#Event ID 12034: ConnectTobeusedwhenoperationisjustexecutingamethod12034_V1
#Event ID 12035: ConnectTobeusedwhenoperationisjustexecutingamethod12035_V1
#Event ID 12036: ConnectTobeusedwhenoperationisjustexecutingamethod12036_V1
#Event ID 12038: ConnectTobeusedwhenoperationisjustexecutingamethod12038_V1
#Event ID 16385: AmsiStateTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 16386: WDACQueryTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 16387: WDACAuditTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 24578: PowerShellISEOperation24578_V1
#Event ID 24595: PowerShellISEOperation24595_V1
#Event ID 24596: PowerShellISEOperation24596_V1
#Event ID 24597: PowerShellISEOperation24597_V1
#Event ID 24598: PowerShellISEOperation24598_V1
#Event ID 24599: PowerShellISEOperation24599_V1
#Event ID 28673: SerializeordeserializeremotingpayloadRehydration_V1
#Event ID 28674: SerializeordeserializeremotingpayloadRehydration28674_V1
#Event ID 28675: SerializeordeserializeremotingpayloadSerializationsettings_V1
#Event ID 28676: SerializeordeserializeremotingpayloadSerializationsettings28676_V1
#Event ID 28677: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised_V1
#Event ID 28678: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28678_V1
#Event ID 28679: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28679_V1
#Event ID 28680: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28680_V1
#Event ID 28682: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28682_V1
#Event ID 28683: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28683_V1
#Event ID 28684: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28684_V1
#Event ID 32769: task_0Receive
#Event ID 32775: task_0Open
#Event ID 32776: task_0Open
#Event ID 32777: task_0Open
#Event ID 32784: task_0Open
#Event ID 32789: task_0Send
#Event ID 32790: task_0Send
#Event ID 32791: task_0Receive
#Event ID 32792: task_0Receive
#Event ID 32793: task_0ONNECTonnect32793_V1
#Event ID 32800: task_0ONNECTonnect32800_V1
#Event ID 32801: task_0Disconnect32801_V1
#Event ID 32802: task_0Disconnect32802_V1
#Event ID 32803: task_0Disconnect32803_V1
#Event ID 32804: task_0Disconnect32804_V1
#Event ID 32805: task_0ONNECTonnect32805_V1
#Event ID 32849: task_0Send
#Event ID 32850: task_0ONNECTonnect32850_V1
#Event ID 32851: task_0ONNECTonnect32851_V1
#Event ID 32852: task_0ONNECTonnect32852_V1
#Event ID 32853: task_0ONNECTonnect32853_V1
#Event ID 32854: task_0Disconnect32854_V1
#Event ID 32855: task_0Open
#Event ID 32856: task_0Open
#Event ID 32857: task_0Disconnect32857_V1
#Event ID 32865: task_0ONNECTonnect32865_V1
#Event ID 32866: task_0ONNECTonnect32866_V1
#Event ID 32867: task_0Receive
#Event ID 32868: task_0Send
#Event ID 40961: PowerShellConsoleStartupStart_V1
#Message #
Example Event #
{
"system": {
"provider": "PowerShellCore",
"guid": "F90714A8-5509-434A-BF6D-B1624C8A19A2",
"event_source_name": "",
"event_id": 40961,
"version": 1,
"level": 4,
"task": 4,
"opcode": 1,
"keywords": 0,
"time_created": "2023-11-06T01:36:38.224978+00:00",
"event_record_id": 13,
"correlation": {
"ActivityID": "E4DB489E-1037-0001-E00D-EEE43710DA01"
},
"execution": {
"process_id": 20676,
"thread_id": 8100
},
"channel": "PowerShellCore/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 40962: PowerShellConsoleStartupStop_V1
#Message #
Example Event #
{
"system": {
"provider": "PowerShellCore",
"guid": "F90714A8-5509-434A-BF6D-B1624C8A19A2",
"event_source_name": "",
"event_id": 40962,
"version": 1,
"level": 4,
"task": 4,
"opcode": 2,
"keywords": 0,
"time_created": "2023-11-06T01:36:44.837777+00:00",
"event_record_id": 15,
"correlation": {
"ActivityID": "E4DB489E-1037-0001-E00D-EEE43710DA01"
},
"execution": {
"process_id": 20676,
"thread_id": 8100
},
"channel": "PowerShellCore/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 45057: NoneTobeusedwhenanexceptionisraised45057_V1
#Event ID 45058: NoneTobeusedwhenanexceptionisraised45058_V1
#Event ID 45060: NoneTobeusedwhenoperationisjustexecutingamethod45060_V1
#Event ID 45062: NoneTobeusedwhenoperationisjustexecutingamethod45062_V1
#Event ID 45063: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 45064: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 45065: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45065_V1
#Event ID 45072: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45072_V1
#Event ID 45073: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45073_V1
#Event ID 45074: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45074_V1
#Event ID 45075: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45075_V1
#Event ID 45076: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45076_V1
#Event ID 45078: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45078_V1
#Event ID 45079: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45079_V1
#Event ID 45080: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45080_V1
#Event ID 45081: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45081_V1
#Event ID 45082: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45082_V1
#Event ID 45083: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45083_V1
#Event ID 45084: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 45085: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45085_V1
#Event ID 45086: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45086_V1
#Event ID 45087: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45087_V1
#Event ID 45088: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45088_V1
#Event ID 45089: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45089_V1
#Event ID 45090: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45090_V1
#Event ID 45091: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45091_V1
#Event ID 45092: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45092_V1
#Event ID 45093: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45093_V1
#Event ID 45094: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45094_V1
#Event ID 45095: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45095_V1
#Event ID 45096: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45096_V1
#Event ID 45097: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45097_V1
#Event ID 45098: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45098_V1
#Event ID 45100: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45100_V1
#Event ID 45101: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45101_V1
#Event ID 45102: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45102_V1
#Event ID 45104: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45104_V1
#Event ID 45105: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45105_V1
#Event ID 45106: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45106_V1
#Event ID 45107: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45107_V1
#Event ID 45108: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45108_V1
#Event ID 45109: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45109_V1
#Event ID 45110: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45110_V1
#Event ID 45111: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45111_V1
#Event ID 45112: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45112_V1
#Event ID 45113: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45113_V1
#Event ID 45114: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45114_V1
#Event ID 45115: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45115_V1
#Event ID 45116: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45116_V1
#Event ID 45117: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45117_V1
#Event ID 45118: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45118_V1
#Event ID 45119: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45119_V1
#Event ID 45120: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45120_V1
#Event ID 45121: ConfigurationTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 45122: ConfigurationTobeusedwhenoperationisjustexecutingamethod45122_V1
#Event ID 45123: ConfigurationTobeusedwhenoperationisjustexecutingamethod45123_V1
#Event ID 45124: ConfigurationTobeusedwhenoperationisjustexecutingamethod45124_V1
#Event ID 45125: ConfigurationTobeusedwhenoperationisjustexecutingamethod45125_V1
#Event ID 45126: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45126_V1
#Event ID 45127: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45127_V1
#Event ID 45128: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45128_V1
#Event ID 45129: None45129_V1
#Event ID 46341: None46341_V1
#Event ID 46346: None46346_V1
#Event ID 46347: None46347_V1
#Event ID 49153: None49153_V1
#Event ID 53249: PowerShellScheduledJobsTobeusedwhenoperationisjustexecutingamethod_V1
#Event ID 53250: PowerShellScheduledJobsTobeusedwhenoperationisjustexecutingamethod53250_V1
#Event ID 53251: PowerShellScheduledJobsTobeusedwhenanexceptionisraised_V1
#Event ID 53504: PowerShellNamedPipeIPCOpen
#Message #
Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Example Event #
{
"system": {
"provider": "PowerShellCore",
"guid": "F90714A8-5509-434A-BF6D-B1624C8A19A2",
"event_source_name": "",
"event_id": 53504,
"version": 1,
"level": 4,
"task": 111,
"opcode": 10,
"keywords": 0,
"time_created": "2023-11-06T01:36:40.335523+00:00",
"event_record_id": 14,
"correlation": {},
"execution": {
"process_id": 20676,
"thread_id": 16904
},
"channel": "PowerShellCore/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {
"param1": "20676",
"param2": "DefaultAppDomain"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 53505: PowerShellNamedPipeIPCClose
#Event ID 53506: PowerShellNamedPipeIPCTobeusedwhenanexceptionisraised_V1
#Event ID 53507: PowerShellNamedPipeIPCONNECTonnect_V1
#Event ID 53508: PowerShellNamedPipeIPCClose
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID f90714a8-5509-434a-bf6d-b1624c8a19a2
Defined in Program, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.10011.16384, captured 2026-06-02