Skip to content
arrow_back
search
E8-AH-ML2.11 bolt ASD Essential Eight

Centrally log PowerShell module, script block, and transcription events

Ensure logging of PowerShell activities is centralized for monitoring.

record_voice_over

Plain language

Centrally logging PowerShell activities means keeping a record of everything that's done using PowerShell, which is a powerful tool used for managing computers. This is important because if someone with bad intentions uses PowerShell to cause harm, like installing harmful software or stealing information, having these logs helps us catch them and understand what they did.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

PowerShell module logging, script block logging and transcription events are centrally logged.
bolt ASD Essential Eight E8-AH-ML2.11
priority_high

Why it matters

Without centralised PowerShell logging, malicious script blocks/modules may run without detection, delaying investigation and increasing risk of compromise or data theft.

settings

Operational notes

Centrally forward PowerShell module, script block and transcription logs; alert on encoded commands, suspicious download/exec and bypass flags; routinely review for anomalies.

Mapping detail

Mapping

Direction

Controls