PowerShell EncodedCommand Builder
Encode PowerShell scripts into -EncodedCommand format or decode existing encoded commands back to their original scripts. Choose from Standard UTF16LE, Gzip+Base64 compression, or Plain Base64 encoding variants with side-by-side size comparison. Switch between encode and decode modes, copy ready-to-use PowerShell commands, and analyze encoded payloads — all free, private, and no signup required.
Encode PowerShell scripts into -EncodedCommand format or decode existing encoded commands. Choose from Standard UTF16LE, Gzip+Base64 compression, or Plain Base64 encoding variants. Compare sizes, copy ready-to-use commands, and decode payloads back to their original scripts. All browser-local, no signup required.
Paste a PowerShell script above and click Encode to encode it into -EncodedCommand format. Choose from Standard UTF16LE, Gzip+Base64, or Plain Base64 encoding variants. Each variant shows the full PowerShell command with size comparison. Click an example to get started.
Why Use Our PowerShell EncodedCommand Builder?
Instant PowerShell Encoding
Encode any PowerShell script into -EncodedCommand format instantly. Supports UTF16LE (standard PowerShell format), Gzip+Base64 compression, and plain Base64 encoding. Paste your script, choose your variant, and get the encoded command ready to execute.
Secure & Private Encoding
All PowerShell script encoding happens entirely in your browser. Your PowerShell code, encoded commands, and decoded outputs never leave your device. No data uploaded to any server, no tracking, no signup required — complete privacy for all your PowerShell script obfuscation work.
PowerShell Command Builder Online - No Installation
Use the PowerShell EncodedCommand Builder directly in any modern browser with no downloads, apps, or plugins required. Features multiple encoding variants, a decode mode to reverse encoded commands, size comparison between formats, and one-click copy for all variants.
3 Encoding Variants with Size Analysis
Supports Standard UTF16LE encoding for direct -EncodedCommand use, Gzip+Base64 for compressed payloads that minimize size, and plain Base64 for basic obfuscation. Side-by-side comparison with character count, size analysis, and best-variant recommendations.
Common Use Cases for PowerShell EncodedCommand Builder
Security Research & Malware Analysis
Security researchers analyze PowerShell-encoded malware by decoding EncodedCommand payloads to reveal hidden scripts. Understanding how attackers encode their PowerShell payloads is essential for threat detection and building effective defense signatures.
Offensive Security Penetration Testing
Penetration testers encode PowerShell payloads using EncodedCommand to evade EDR and antivirus signature detection. Encoding obfuscates the script content, bypassing string-based detection rules while maintaining full script functionality.
CTF Challenge Creation
Capture The Flag challenge authors encode PowerShell scripts as EncodedCommand payloads for reverse engineering challenges. Participants decode and reverse engineer the payload to understand the script's purpose and find the flag.
Script Distribution & Deployment
System administrators use EncodedCommand to distribute and execute PowerShell scripts in restricted environments where script execution policies or character limitations prevent direct script pasting. Encoding ensures the script arrives intact.
Bypassing Execution Restrictions
PowerShell EncodedCommand can sometimes bypass execution policy restrictions and character limitations in command injection scenarios. Encoded commands avoid problematic characters and can be embedded in URLs, command lines, and configuration values.
Educational Tool for PowerShell Internals
Learn how PowerShell's -EncodedCommand parameter works under the hood. Understand UTF16LE encoding, Base64 conversion, and how PowerShell decodes and executes encoded scripts. Compare different encoding variants and their size trade-offs.
Understanding PowerShell EncodedCommand
What is PowerShell -EncodedCommand?
PowerShell -EncodedCommand (also known as -Enc or -EC) is a parameter that accepts a Base64-encoded string representing a UTF-16LE encoded PowerShell script. Instead of passing a plain-text command, you pass a long Base64 string that PowerShell decodes at runtime. The command powershell -EncodedCommand SQBkAE8AbgBl... is equivalent to powershell -Command "I dO nE..." but completely hides the actual script content from casual inspection. This makes it a popular technique for obfuscating PowerShell commands in both legitimate deployment scripts and malicious payloads.
Our PowerShell EncodedCommand Builder generates 3 encoding variants for any PowerShell script. Each variant is a valid PowerShell command that produces the same script output. Compare the encoded sizes, decode existing commands, and copy the variant that best fits your needs. All processing runs locally in your browser with no data sent to any server.
How Our PowerShell EncodedCommand Builder Works
- 1. Enter Your PowerShell Script: Type or paste the PowerShell script you want to encode into the input field. The tool automatically detects whether your input is a script to encode or an encoded command to decode. Example scripts are provided to demonstrate different encoding variants in action.
- 2. Select Encoding Variant: Choose from 3 encoding variants via method cards. Standard UTF16LE produces a canonical -EncodedCommand-compatible string. Gzip+Base64 compresses the script before encoding for smaller payloads. Plain Base64 offers basic encoding without PowerShell-specific formatting. Each card shows the generated command with size comparison to the original.
- 3. Copy & Use: Click the Copy button next to any encoded variant to copy the full PowerShell command to your clipboard. Each variant is displayed as a ready-to-use PowerShell command line with size analysis. You can also paste an existing EncodedCommand string to decode it back to its original script.
Encoding Variants Explained
- Standard UTF16LE: The official PowerShell -EncodedCommand format. The script is converted to UTF-16LE bytes and then Base64-encoded. PowerShell decodes this natively with
[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String($encoded)). Most commonly used in legitimate deployment scripts and malware alike. - Gzip + Base64: The script is first compressed using Gzip (deflate) and then Base64-encoded. This produces the smallest payload size — often 60-80% smaller than UTF16LE for large scripts. Requires PowerShell to decompress at runtime using
System.IO.Compression.GzipStream. Ideal for size-constrained environments like command injection payloads. - Plain Base64: The script is encoded using standard Base64 without UTF16LE conversion. The simplest encoding variant. PowerShell decodes it with
[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($encoded)). Best for simple obfuscation where -EncodedCommand compatibility is not required.
Privacy, Security & Availability
The PowerShell EncodedCommand Builder is 100% free with no signup required. All encoding and decoding is performedlocally in your browser — your PowerShell script and encoded output never leave your device. There areno usage limits or restrictions. The tool supports 3 encoding variants with side-by-side comparison, character count and size statistics, decode mode to reverse existing EncodedCommand strings, and example presets. Use it as many times as you need for your security research, development, or educational purposes.
Frequently Asked Questions About PowerShell EncodedCommand Builder
PowerShell -EncodedCommand (also -Enc or -EC) is a command-line parameter that accepts a Base64-encoded string representing UTF-16LE encoded PowerShell commands. Instead of passing a plain-text command that anyone can read in process listings or logs, you pass a long Base64 string that PowerShell decodes internally before execution. This hides the script content from casual inspection and avoids issues with special characters in command-line arguments.
The tool supports 3 encoding variants: Standard UTF16LE encoding (the official -EncodedCommand format using UTF-16LE + Base64), Gzip + Base64 compression (compresses the script with Gzip before Base64 encoding for 60-80% smaller payloads), and Plain Base64 (simple Base64 encoding without UTF16LE conversion for basic obfuscation). Each variant includes the PowerShell command to invoke it.
Yes, the tool includes a decode mode. Paste an existing PowerShell EncodedCommand string (or any Base64-encoded PowerShell payload) into the input field, and the tool will automatically detect whether it is UTF16LE, Gzip+Base64, or plain Base64 encoded, then decode it back to the original script. This is useful for analyzing encoded commands found in security research or threat intelligence.
Gzip + Base64 consistently produces the smallest payload — typically 60-80% smaller than UTF16LE encoding. For example, a 1KB PowerShell script becomes about 2KB in UTF16LE format, but only about 500-700 bytes with Gzip+Base64. Plain Base64 is the largest format since it includes both encoding overhead and requires additional PowerShell decode commands. However, Gzip+Base64 requires PowerShell 3.0+ for the System.IO.Compression assembly.
Modern EDR and antivirus tools can detect -EncodedCommand usage through process command-line monitoring, behavioral analysis, and machine learning models trained on encoded payload patterns. While encoding bypasses simple string-based detection, it is not a guarantee against advanced security products. Combining encoding with additional obfuscation techniques like variable splitting, string concatenation, and invocation obfuscation provides defense in depth.
Yes, -EncodedCommand works identically in both Windows PowerShell (powershell.exe) and PowerShell Core 7+ (pwsh.exe). The encoding format is the same — UTF16LE + Base64. PowerShell 7 also supports the -EncodedCommand parameter for cross-platform compatibility on Linux and macOS.
Absolutely. The PowerShell EncodedCommand Builder runs entirely in your browser. Your PowerShell scripts, encoded commands, and decoded outputs are never sent to any server, stored in any database, or tracked in any way. All processing happens locally on your device using client-side JavaScript. No signup required, no data collection, no analytics.
Yes — 100% free with no signup, no account, and no usage limits. Encode as many PowerShell scripts as you need, as many times as you want. All 3 encoding variants, decode mode, size comparison, and copy functionality are available without any restrictions. No premium tiers, no hidden charges, no rate limits of any kind.