Skip to content
Security

Event ID 4688: Process creation

A new process has been createdSecurity event 4688 logs every new process: executable, parent, account, elevation and, if enabled, the full command line. Off by default.
4688
Event ID
4688
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Processes
Default logging
Needs configuration

What event 4688 means

Event 4688 is the native Windows record of process execution. Each record names the new executable (NewProcessName), the process that started it (ProcessId and, from Windows 10 / Server 2016, ParentProcessName), the account and logon session (SubjectUserName, SubjectLogonId), and the token it received (TokenElevationType, MandatoryLabel).

The most valuable field, CommandLine, is empty unless a separate policy is enabled: "Include command line in process creation events". Without it you know that powershell.exe ran but not what it ran. Enabling both the audit subcategory and the command-line policy turns 4688 into a lightweight alternative to Sysmon event 1 (which adds hashes and parent command line).

When the creator and the new process run under different logon sessions (for example a service launching a process as another user), the Target* fields name the account the process actually runs as; otherwise they are empty. SubjectLogonId / TargetLogonId tie each process back to its 4624 logon.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Detailed Tracking > Audit Process Creation (Success). For command lines also enable Computer Configuration > Administrative Templates > System > Audit Process Creation > Include command line in process creation events.

Not enabled in the default audit policy. CommandLine exists from Windows 8.1 / Server 2012 R2 (event version 1); Target* fields, ParentProcessName and MandatoryLabel from Windows 10 / Server 2016 (version 2). Volume is high — plan log size and forwarding accordingly. Command lines can contain secrets typed as arguments.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that created the process (the creator). HOST$ means SYSTEM or another machine-context service.
SubjectLogonIdCreator's logon session. Match it to TargetLogonId in 4624 to learn how the session started (interactive, RDP, network, service).
NewProcessIdHexadecimal PID of the new process. Match it to ProcessId in 4689 for the exit, or to later child processes.
NewProcessNameFull path of the new executable. Check the folder as much as the name.
TokenElevationTypeWhat kind of token the process received under UAC.
ValueMeaning
%%1936Type 1, full token — UAC is off for this account, or the account is the built-in Administrator, a service account or SYSTEM.
%%1937Type 2, elevated token — the user started the program with Run as administrator, or the program requires elevation and the user is an administrator.
%%1938Type 3, limited token — UAC is on and the process runs with administrative rights stripped.
MandatoryLabelIntegrity level of the new process.
ValueMeaning
S-1-16-0Untrusted.
S-1-16-4096Low integrity (e.g. sandboxed browser processes).
S-1-16-8192Medium integrity — standard user processes.
S-1-16-8448Medium plus.
S-1-16-12288High integrity — elevated administrator processes.
S-1-16-16384System integrity — SYSTEM services.
S-1-16-20480Protected process.
ProcessIdHexadecimal PID of the creator (parent) process. PIDs are reused, so match it to the parent's own 4688 by time as well.
ParentProcessNameFull path of the creator process (Windows 10 / Server 2016 and later).
CommandLineFull command line of the new process. Empty unless the command-line policy is enabled; check it first when it is present.
TargetUserNameAccount the new process runs as when it differs from the creator's session; - when the creator and new process share the same logon.
TargetLogonIdLogon session of the new process when it differs from the creator's; 0x0 otherwise.

Common benign sources

  • Normal user and system activity — thousands of records per day per host, dominated by services, updaters and browsers.
  • Software deployment and management agents (SCCM, Intune, backup, monitoring) spawning cmd.exe or powershell.exe as SYSTEM.
  • Administrators running tools with Run as administrator, producing %%1937 elevated tokens.

What attackers do that produces it

  • Living-off-the-land execution: powershell.exe with -enc or download cradles, rundll32.exe, regsvr32.exe, mshta.exe, certutil.exe used with unusual arguments.
  • Office applications, browsers or w3wp.exe spawning command interpreters — a common sign of malicious documents or web shells.
  • Remote execution artifacts on the target: children of services.exe with random names (PsExec-style), WmiPrvSE.exe spawning cmd.exe (WMI), wsmprovhost.exe (WinRM).
  • Discovery bursts from one session — whoami, net, nltest, ipconfig, systeminfo within seconds.
  • Executables running from user-writable locations such as %TEMP%, AppData, C:\ProgramData or C:\Users\Public.

Investigation tips

  • Rebuild the process tree with NewProcessId / ProcessId and ParentProcessName, remembering that PIDs are reused over time.
  • Group by SubjectLogonId to see everything a single session ran, then pivot to the 4624 that created that session to learn its origin.
  • Look for rare parent/child pairs across the fleet rather than individual suspicious names.
  • If CommandLine is empty everywhere, the command-line policy is off — fall back to Sysmon 1, PowerShell 4104 or EDR data.
  • Use 4689 with the same PID to get the exit time and duration of short-lived tools.

MITRE ATT&CK techniques

TechniqueTactics
T1059 Command and Scripting InterpreterExecution
T1059.001 Command and Scripting Interpreter: PowerShellExecution
T1059.003 Command and Scripting Interpreter: Windows Command ShellExecution
T1218 System Binary Proxy ExecutionStealth
T1047 Windows Management InstrumentationExecution
T1569.002 System Services: Service ExecutionExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1182 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 24
  • High · 587
  • Medium · 512
  • Low · 58
  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4688: A new process has been created (command line)

Sources and further reading