PowerShell ScriptBlock Analyzer
Analyze PowerShell script block logging output to detect and decode obfuscation techniques. Automatically identifies Base64 EncodedCommand payloads, backtick escape obfuscation, [char] code point concatenation, variable string construction, .Replace() manipulation, Unicode escape sequences, split/join patterns, Invoke-Expression calls, and format operator obfuscation. Each detection includes confidence ratings, decoded values, and source context. Free, private, and no signup required.
Analyze PowerShell script block logging output to detect and decode obfuscation techniques. Automatically identifies Base64 EncodedCommand payloads, backtick escape obfuscation, [char] concatenation, variable string construction, .Replace() manipulation, Unicode escape sequences, split/join patterns, Invoke-Expression calls, and format operator obfuscation. Each detection includes confidence ratings, decoded values, and source context.
Paste PowerShell script block logging output above and click Analyze ScriptBlock to automatically detect and decode obfuscation techniques. The tool identifies Base64 EncodedCommand payloads, backtick escapes, [char] concatenation, variable string construction, .Replace() manipulation, Unicode escapes, split/join patterns, Invoke-Expression calls, and format operator obfuscation. Try loading an example to see how it works!
PowerShell ScriptBlock Analyzer Features
9 Obfuscation Techniques
Detects Base64 EncodedCommand payloads, backtick escapes, [char] concatenation, variable string construction, .Replace() manipulation, Unicode escapes (`uXXXX), split/join patterns, Invoke-Expression calls, and -f format operator obfuscation. Comprehensive coverage of common PowerShell obfuscation methods.
Confidence Scoring System
Each detection is rated from Very High (5) to Very Low (1). Base64 payloads that decode to executable commands score highest. Backtick escapes and [char] concatenation score high. String replacement and format operator patterns score medium to low for nuanced analysis.
Annotated & Beautified Output
Two output views: Annotated Code shows original log lines with inline detection markers and explanations. Beautified Output strips backtick escapes, consolidates variable constructions, and expands IEX to Invoke-Expression for immediate readability.
ScriptBlock Log Analysis
Designed specifically for PowerShell ScriptBlock logging (ScriptBlock Logging) output. Parses multi-line log entries, command lines, and script blocks to extract and analyze obfuscated commands. Includes source line numbers and surrounding context for every detection.
Use Cases
Incident Response
Security analysts use this tool during incident response to quickly decode obfuscated PowerShell commands extracted from script block logs. Determines the intent and scope of malicious PowerShell activity in minutes.
Malware Analysis
Reverse engineer obfuscated PowerShell payloads used in malware campaigns. Detects Base64-encoded download cradles, backtick-obfuscated command names, and [char]-constructed strings to reveal the actual malicious behavior.
Threat Hunting
Proactively hunt for obfuscated PowerShell in your environment. Paste script block log entries from SIEM or EDR tools to identify hidden Invoke-Expression calls, encoded commands, and string manipulation patterns.
Security Training & Education
Use real-world PowerShell obfuscation examples to train security teams. See exactly how each technique works, what the decoded output looks like, and how to spot obfuscation patterns in log data.
Red Team Engagements
Red team operators can verify that their PowerShell obfuscation techniques are effective by running them through the analyzer. See how blue team tools would detect and decode the obfuscation.
Log & SIEM Analysis
Analyze PowerShell ScriptBlock logging output from Windows Event Logs (Event ID 4104) or SIEM platforms. Extract and decode obfuscated commands from multi-line log entries for further investigation.
About the PowerShell ScriptBlock Analyzer
What is PowerShell ScriptBlock Logging?
PowerShell ScriptBlock Logging is a Windows security feature that records the content of all PowerShell script blocks executed on a system. When enabled, Windows Event Log (Event ID 4104) captures the actual PowerShell commands run, including obfuscated commands. Attackers use various techniques to hide their intent within these logs, making analysis difficult without dedicated tools.
How the Analyzer Works
The analyzer scans PowerShell script block log input for 9 common obfuscation techniques. It parses each line, applies regex-based detection patterns, attempts to decode Base64 payloads (including UTF-16LE format used by -EncodedCommand), identifies structural patterns like backtick escapes and [char] concatenation, and presents each finding with contextual information. All processing is done client-side.
Common PowerShell Obfuscation Techniques
PowerShell obfuscation ranges from simple backtick escapes (Inv`oke-Expr`ession) to complex Base64-encoded commands (-EncodedCommand), [char] code point concatenation, variable string fragmentation, .Replace() manipulation, Unicode escape sequences (`uXXXX), split/join rearrangements, Invoke-Expression calls, and -f format operator tricks. Understanding these patterns is essential for security analysis.
Privacy & Security
This tool runs entirely in your browser. PowerShell script block logs, decoded commands, and all analysis results never leave your device. No data is uploaded to any server, no analytics are collected, and no signup is required. This is particularly important when analyzing potentially malicious or sensitive security data.
Related Deobfuscation Tools
PowerShell Deobfuscator / Script Decoder
Detect and reverse PowerShell obfuscation: Base64, [char] strings, backtick escapes, XOR cipher patterns, and nested encoding.
Phishing URL Detector
Analyze URLs for phishing indicators: homoglyph domains, encoding abuse, suspicious TLDs, and keyword deception.
Obfuscated Text Diff & Comparison
Compare two text versions to detect invisible differences: zero-width characters, homoglyph substitutions, and encoding variations.
Binary Data Unpacker
Detect and unpack obfuscated binary data. Supports Base64, hex, XOR, GZIP, and more with confidence scoring.
The tool detects nine common techniques: Base64 EncodedCommand payloads (including UTF-16LE encoded commands), backtick escape obfuscation (Inv`oke-Expr`ession), [char] integer code point concatenation, variable string construction across multiple variables, .Replace() string manipulation, Unicode escape sequences (`uXXXX format), split/join string rearrangement, Invoke-Expression/IEX calls, and -f format operator patterns. Each detection includes confidence scoring and decoded output.
The analyzer scans for -EncodedCommand parameter followed by a Base64 string. It first attempts UTF-16LE decoding (PowerShell's standard -EncodedCommand format), checking for the characteristic null-byte pattern of UTF-16LE. If that fails, it tries plain Base64 decoding. Successfully decoded commands are displayed with the decoded script content. The detection also catches [System.Convert]::FromBase64String decode patterns used within scripts.
Confidence scores range from 1 to 5. Score 5 (Very High) is assigned when Base64 payloads decode to executable PowerShell commands or when Invoke-Expression/IEX is detected. Score 4 (High) is for backtick escapes and [char] concatenation with clear decoding. Score 3 (Medium) covers variable string construction and .Replace() patterns. Score 2 (Low) is for split/join and format operator patterns that may have legitimate uses.
Annotated Code displays the original script block log with inline comments added before each line where obfuscation was detected, showing the technique name and description. Beautified Output strips backtick escapes, consolidates variable constructions into combined strings, expands IEX to Invoke-Expression for clarity, and removes excessive whitespace for an immediately readable version of the commands.
No. The tool covers the most common PowerShell obfuscation patterns but cannot handle all methods. It cannot decode dynamically generated code (via Add-Type or reflection), COM object manipulation, encrypted payloads without runtime execution, or advanced techniques that reconstruct commands at runtime through complex logic. Some obfuscation may require dynamic analysis in a PowerShell environment.
PowerShell ScriptBlock logs are generated by Windows Event Logging when ScriptBlock Logging is enabled (Event ID 4104). They can also be obtained from EDR platforms like Microsoft Defender for Endpoint, Sentinel, or any SIEM that collects PowerShell operational logs. The logs contain the full text of script blocks executed by PowerShell, including obfuscated commands.
Absolutely. The PowerShell ScriptBlock Analyzer runs entirely in your browser. Your log data, all detected indicators, decoded values, and analysis results are never uploaded to any server or transmitted over the network. All processing happens locally on your device with no API calls, data collection, or telemetry. This is critical when analyzing security-sensitive data from incident investigations.
Yes - 100% free with no signup, no account, and no usage limits. Analyze as many PowerShell script block logs as you need, as many times as you want. There are no premium tiers, hidden charges, or rate limits. The tool runs entirely in your browser - your data never leaves your device.