// REFERENCE
4103 — PowerShell module logging
Log: PowerShell/Operational
Medium risk
PowerShell module/pipeline invocation logging (Operational log). It captures commands and their arguments after alias resolution, useful to see real intent even with light obfuscation. Complements 4104.
Related tools
Work with this in:
Related
400
400 — PowerShell engine started 800
800 — PowerShell pipeline execution details 4104
4104 — PowerShell script block logging
400 — PowerShell engine started 800
800 — PowerShell pipeline execution details 4104
4104 — PowerShell script block logging
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.