// REFERENCE
400 — PowerShell engine started
Log: Windows PowerShell
Low risk
The PowerShell engine started (classic Windows PowerShell log). The HostApplication field reveals how it was invoked; an unusual host or flags like -enc or -nop are hints of malicious execution. Handy on hosts without script block logging.
Related tools
Work with this in:
Related
800
800 — PowerShell pipeline execution details 4103
4103 — PowerShell module logging 4104
4104 — PowerShell script block logging
800 — PowerShell pipeline execution details 4103
4103 — PowerShell module logging 4104
4104 — PowerShell script block logging
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.