Event ID 4608: Windows starting up
- Event ID
- 4608
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- System
- Default logging
- Logged by default
What event 4608 means
Event 4608 is written when lsass.exe starts and the auditing subsystem initializes, which happens early in every boot. It has no event data; its value is purely as a timestamp that says "the machine started here".
Paired with 1100 (Event Log service shut down) it brackets each reboot on the Security log timeline. A 4608 with no 1100 before it indicates the previous session ended uncleanly — crash, power loss or forced reset — which System events 41 and 6008 will confirm.
During an investigation, reboots matter: they end every logon session, restart persistence mechanisms (services, run keys, startup tasks) and are sometimes forced by attackers to activate a driver, a boot configuration change or a ransomware payload.
When it is logged
Advanced Audit Policy Configuration > System > Audit Security State Change (Success). Enabled for Success in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| TimeCreated | The System/TimeCreated timestamp is the only useful data — EventData is empty. It marks when auditing came up during boot, shortly after the kernel started. |
Common benign sources
- Every normal boot, including restarts after patching and VM starts.
- Frequent startups on laptops and virtual desktops that are powered off daily.
What attackers do that produces it
- A reboot forced shortly after a new service, driver or boot configuration change, to load a persistence mechanism or bootkit.
- Ransomware restarting a host (sometimes into Safe Mode) to encrypt without interference.
Investigation tips
- Build a boot timeline from 4608, System 6005/6006 and 12/13, and look for reboots at unusual times.
- Check whether a 1100 precedes each 4608; a missing one means an unclean shutdown worth explaining (System 41, 6008).
- Look at what changed just before an unexpected reboot — 4697/7045 service installs, 4826 boot settings, 4688 of
shutdown.exeorbcdedit.exe.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.
Related events
- 1100Event logging service shut downSecurity
- 4826Boot configuration loadedSecurity
- 12Operating system startedSystem
- 13Operating system shutdownSystem
- 6005Event Log service startedSystem
- 6006Event Log service stoppedSystem
- 6008Unexpected shutdownSystem
- 41Unclean reboot (Kernel-Power)System
- 1074Shutdown or restart requestedSystem