// REFERENCE

400 — PowerShell engine started

Log: Windows PowerShell Low risk

The PowerShell engine started (classic Windows PowerShell log). The HostApplication field reveals how it was invoked; an unusual host or flags like -enc or -nop are hints of malicious execution. Handy on hosts without script block logging.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.