PowerShell History script

Prev Next

The PowerShell History script acquires data from event logs specific to PowerShell history when the script is enabled on host endpoints. This script can be requested for Windows host endpoints only.

Note

PowerShell History script support is not provided for macOS or Linux host endpoints.

You cannot copy, edit, reset, import, or delete the PowerShell History script or use this script in data acquisition scripts you create. This script does not appear on the Data Acquisition Scripts page.

HX_SSType_PowerShell_scap.png

Requesting PowerShell History data

To request PowerShell History data using the Web UI:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select one or more hosts.

  3. From the Actions menu, select PowerShell History. Alternatively, you can select PowerShell History from the Acquire menu on a host details page.

  4. Click Go to access the Acquire PowerShell History dialog box.

  5. In the Comment field, enter the reason you want to acquire the file and log details about the data acquisition request that you want to track.

  6. Click Acquire to submit the request.

PowerShell History data can be requested as a regular data acquisition. See Requesting a data acquisition.