DFIR Reference v0.1

PowerShell Event Reference

Cross-channel reference for PowerShell forensic analysis. Covers Microsoft-Windows-PowerShell/Operational (script block and module logging), the legacy Windows PowerShell log, and the separate PowerShellCore/Operational channel used by PowerShell 7 — a commonly missed gap when monitoring only the classic PowerShell log.

11Event IDs
3Log Channels
6Sigma Rules
PowerShell/OperationalPowerShellCore/OperationalWindows PowerShell (classic)
Showing 11 of 11 events

⚡ Sigma Detection Rules — PowerShell Event Reference

Curated highest-signal Sigma-style detection rules for PowerShell Event Reference activity, based on patterns from SigmaHQ/sigma. Click any Event ID chip to jump to that event in the reference tab.

Convert to your SIEM: sigconverter.io

6 detection rules 3 event IDs covered
Copied!