← Event ID reference
4688

A new process has been created

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Tampering & persistence
  • Info

What it means

A program started. With command-line auditing enabled, the full command line is included.

Why it matters

One of the most valuable events for investigations: shows exactly what ran.

What to do

  • Enable "Include command line in process creation events" by Group Policy.
  • Watch for Office apps launching powershell.exe or cmd.exe.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4688
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us