I'm not sure there is. As a test, I shutdown my second PC and reviewed the logs and while it listed which account executed the command, no PC was listed.
If there is firewall software installed on your PC and it's running, perhaps it logged something
From here Every time when you execute remote operation with PsShutdown, it installs and starts service on target PCs though an access to their Admin$ shares. Then PsShutdown sends command to service and once operation is complete, it stops and uninstall service.
I think, you should look for service creation and deletion. It works if you have user privilege auditing enabled, which by default is off on workstations.
If you go into Event Viewer try looking for an Event ID "4674" or "7035." I don't think it will tell you were the command came from exactly, but if you filter through the tabs you might get something.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.