Where can I find the PowerShell command history?

More in Windows
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- A look inside ESE
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need…
- ::%16777216 — so what exactly are you?
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use…
- Confusion in WSUS vulnerabilities: setting the record straight
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in…
- Disabling Defender / MpPreference
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Surely the first things that come to mind are Windows logs and the
ConsoleHost_history.txt file, but there is another rather interesting artifact.We are talking about the PowerShell Transcript log. It is a text file into which data about the commands executed during a PowerShell session is written.
In the PowerShell Transcript, we can find such interesting information as:
• the name of the user who executed the commands;
• the start and end time of data logging;
• the entered commands and the result of their execution.
It is worth noting that this logging mechanism is disabled by default. To enable it, you need to set the value
EnableTranscripting = 1 (REG_DWORD) in the Windows registry key HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription.By default, log files are written to the directory
\Users\[username]\Documents\[YYYYMMDD]. But this path can be changed by specifying the required directory in the OutputDirectory value of the HKLM\Software\Policies\Microsoft\Windows\PowerShell\Transcription key.Example log:
**********************
Windows PowerShell transcript start
Start time: 20240802191321
Username: TEST\User
RunAs User: TEST\User
Configuration Name:
Machine: PC1 (Microsoft Windows NT 10.0.17763.0)
Host Application: powershell New-ItemProperty -Path HKLM:\System\CurrentControlSet\Control\Lsa -Name DisableRestrictedAdmin -Value 0 -PropertyType DWORD -Force
Process ID: 13612
PSVersion: 5.1.17763.2931
PSEdition: Desktop
PSCompatibleVersions: 1.0, 2.0, 3.0, 4.0, 5.0, 5.1.17763.2931
BuildVersion: 10.0.17763.2931
CLRVersion: 4.0.30319.42000
WSManStackVersion: 3.0
PSRemotingProtocolVersion: 2.3
SerializationVersion: 1.1.0.1
**********************
PS>New-ItemProperty -Path HKLM:\System\CurrentControlSet\Control\Lsa -Name DisableRestrictedAdmin -Value 0 -PropertyType DWORD -Force
DisableRestrictedAdmin : 0
PSPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
PSParentPath : Microsoft.PowerShell.Core\Registry::HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control
PSChildName : Lsa
PSDrive : HKLM
PSProvider : Microsoft.PowerShell.Core\Registry
PS>$global:?
True
**********************
Windows PowerShell transcript end
End time: 20240801913322
**********************
Code language: PowerShell (powershell)#tips #win
@ptescalator
More in Windows
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- A look inside ESE
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need…
- ::%16777216 — so what exactly are you?
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use…
- Confusion in WSUS vulnerabilities: setting the record straight
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in…
- Disabling Defender / MpPreference
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…





