[ << ALL_FEED ]

Where can I find the PowerShell command history?

More in Windows

Where can the history of PowerShell commands be found? 🧐

Surely the first things that come to mind are Windows logs and the ConsoleHost_history.txt file, but there is another rather interesting artifact.

We are talking about the PowerShell Transcript log. It is a text file into which data about the commands executed during a PowerShell session is written.

In the PowerShell Transcript, we can find such interesting information as:

• the name of the user who executed the commands;
• the start and end time of data logging;
• the entered commands and the result of their execution.

It is worth noting that this logging mechanism is disabled by default. To enable it, you need to set the value EnableTranscripting = 1 (REG_DWORD) in the Windows registry key HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription.

By default, log files are written to the directory \Users\[username]\Documents\[YYYYMMDD]. But this path can be changed by specifying the required directory in the OutputDirectory value of the HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription key.

Example log:


**********************
Windows PowerShell transcript start
Start time: 20240802191321
Username: TEST\User
RunAs User: TEST\User
Configuration Name: 
Machine: PC1 (Microsoft Windows NT 10.0.17763.0)
Host Application: powershell New-ItemProperty -Path HKLM:\System\CurrentControlSet\Control\Lsa -Name DisableRestrictedAdmin -Value 0 -PropertyType DWORD -Force
Process ID: 13612
PSVersion: 5.1.17763.2931
PSEdition: Desktop
PSCompatibleVersions: 1.0, 2.0, 3.0, 4.0, 5.0, 5.1.17763.2931
BuildVersion: 10.0.17763.2931
CLRVersion: 4.0.30319.42000
WSManStackVersion: 3.0
PSRemotingProtocolVersion: 2.3
SerializationVersion: 1.1.0.1
**********************
PS>New-ItemProperty -Path HKLM:\System\CurrentControlSet\Control\Lsa -Name DisableRestrictedAdmin -Value 0 -PropertyType DWORD -Force


DisableRestrictedAdmin : 0
PSPath                 : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
PSParentPath           : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control
PSChildName            : Lsa
PSDrive                : HKLM
PSProvider             : Microsoft.PowerShell.Core\Registry



PS>$global:?
True
**********************
Windows PowerShell transcript end
End time: 20240801913322
**********************
Code language: PowerShell (powershell)


#tips #win
@ptescalator

More from global_author

More from global_author

More in Windows