4688
A new process has been created
- Log: Security
- Source: Microsoft-Windows-Security-Auditing
- Tampering & persistence
- Info
What it means
A program started. With command-line auditing enabled, the full command line is included.
Why it matters
One of the most valuable events for investigations: shows exactly what ran.
What to do
- Enable "Include command line in process creation events" by Group Policy.
- Watch for Office apps launching powershell.exe or cmd.exe.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Security'; Id = 4688
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Source
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us