// REFERENCE
800 — PowerShell pipeline execution details
Log: Windows PowerShell
Medium risk
Details of a PowerShell pipeline execution (classic log). It records executed commands when module logging is on; an alternative to 4103 on older systems to see what actually ran.
Related tools
Work with this in:
Related
400
400 — PowerShell engine started 4103
4103 — PowerShell module logging 4104
4104 — PowerShell script block logging
400 — PowerShell engine started 4103
4103 — PowerShell module logging 4104
4104 — PowerShell script block logging
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.