Skip to content
Security

Event ID 4608: Windows starting up

Windows is starting upSecurity event 4608 is logged when LSASS starts and auditing initializes during boot. Use it to mark system startups on the Security log timeline.
4608
Event ID
4608
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
System
Default logging
Logged by default

What event 4608 means

Event 4608 is written when lsass.exe starts and the auditing subsystem initializes, which happens early in every boot. It has no event data; its value is purely as a timestamp that says "the machine started here".

Paired with 1100 (Event Log service shut down) it brackets each reboot on the Security log timeline. A 4608 with no 1100 before it indicates the previous session ended uncleanly — crash, power loss or forced reset — which System events 41 and 6008 will confirm.

During an investigation, reboots matter: they end every logon session, restart persistence mechanisms (services, run keys, startup tasks) and are sometimes forced by attackers to activate a driver, a boot configuration change or a ransomware payload.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > System > Audit Security State Change (Success). Enabled for Success in the default Windows audit policy.

Key fields

FieldWhat it tells you
TimeCreatedThe System/TimeCreated timestamp is the only useful data — EventData is empty. It marks when auditing came up during boot, shortly after the kernel started.

Common benign sources

  • Every normal boot, including restarts after patching and VM starts.
  • Frequent startups on laptops and virtual desktops that are powered off daily.

What attackers do that produces it

  • A reboot forced shortly after a new service, driver or boot configuration change, to load a persistence mechanism or bootkit.
  • Ransomware restarting a host (sometimes into Safe Mode) to encrypt without interference.

Investigation tips

  • Build a boot timeline from 4608, System 6005/6006 and 12/13, and look for reboots at unusual times.
  • Check whether a 1100 precedes each 4608; a missing one means an unclean shutdown worth explaining (System 41, 6008).
  • Look at what changed just before an unexpected reboot — 4697/7045 service installs, 4826 boot settings, 4688 of shutdown.exe or bcdedit.exe.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading