Event ID 4688: Process creation
- Event ID
- 4688
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 4688 means
Event 4688 is the native Windows record of process execution. Each record names the new executable (NewProcessName), the process that started it (ProcessId and, from Windows 10 / Server 2016, ParentProcessName), the account and logon session (SubjectUserName, SubjectLogonId), and the token it received (TokenElevationType, MandatoryLabel).
The most valuable field, CommandLine, is empty unless a separate policy is enabled: "Include command line in process creation events". Without it you know that powershell.exe ran but not what it ran. Enabling both the audit subcategory and the command-line policy turns 4688 into a lightweight alternative to Sysmon event 1 (which adds hashes and parent command line).
When the creator and the new process run under different logon sessions (for example a service launching a process as another user), the Target* fields name the account the process actually runs as; otherwise they are empty. SubjectLogonId / TargetLogonId tie each process back to its 4624 logon.
When it is logged
Advanced Audit Policy Configuration > Detailed Tracking > Audit Process Creation (Success). For command lines also enable Computer Configuration > Administrative Templates > System > Audit Process Creation > Include command line in process creation events.
Not enabled in the default audit policy. CommandLine exists from Windows 8.1 / Server 2012 R2 (event version 1); Target* fields, ParentProcessName and MandatoryLabel from Windows 10 / Server 2016 (version 2). Volume is high — plan log size and forwarding accordingly. Command lines can contain secrets typed as arguments.
Key fields
| Field | What it tells you | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that created the process (the creator). HOST$ means SYSTEM or another machine-context service. | ||||||||||||||||
| SubjectLogonId | Creator's logon session. Match it to TargetLogonId in 4624 to learn how the session started (interactive, RDP, network, service). | ||||||||||||||||
| NewProcessId | Hexadecimal PID of the new process. Match it to ProcessId in 4689 for the exit, or to later child processes. | ||||||||||||||||
| NewProcessName | Full path of the new executable. Check the folder as much as the name. | ||||||||||||||||
| TokenElevationType | What kind of token the process received under UAC.
| ||||||||||||||||
| MandatoryLabel | Integrity level of the new process.
| ||||||||||||||||
| ProcessId | Hexadecimal PID of the creator (parent) process. PIDs are reused, so match it to the parent's own 4688 by time as well. | ||||||||||||||||
| ParentProcessName | Full path of the creator process (Windows 10 / Server 2016 and later). | ||||||||||||||||
| CommandLine | Full command line of the new process. Empty unless the command-line policy is enabled; check it first when it is present. | ||||||||||||||||
| TargetUserName | Account the new process runs as when it differs from the creator's session; - when the creator and new process share the same logon. | ||||||||||||||||
| TargetLogonId | Logon session of the new process when it differs from the creator's; 0x0 otherwise. |
Common benign sources
- Normal user and system activity — thousands of records per day per host, dominated by services, updaters and browsers.
- Software deployment and management agents (SCCM, Intune, backup, monitoring) spawning
cmd.exeorpowershell.exeas SYSTEM. - Administrators running tools with Run as administrator, producing
%%1937elevated tokens.
What attackers do that produces it
- Living-off-the-land execution:
powershell.exewith-encor download cradles,rundll32.exe,regsvr32.exe,mshta.exe,certutil.exeused with unusual arguments. - Office applications, browsers or
w3wp.exespawning command interpreters — a common sign of malicious documents or web shells. - Remote execution artifacts on the target: children of
services.exewith random names (PsExec-style),WmiPrvSE.exespawningcmd.exe(WMI),wsmprovhost.exe(WinRM). - Discovery bursts from one session —
whoami,net,nltest,ipconfig,systeminfowithin seconds. - Executables running from user-writable locations such as
%TEMP%,AppData,C:\ProgramDataorC:\Users\Public.
Investigation tips
- Rebuild the process tree with NewProcessId / ProcessId and ParentProcessName, remembering that PIDs are reused over time.
- Group by SubjectLogonId to see everything a single session ran, then pivot to the 4624 that created that session to learn its origin.
- Look for rare parent/child pairs across the fleet rather than individual suspicious names.
- If CommandLine is empty everywhere, the command-line policy is off — fall back to Sysmon 1, PowerShell 4104 or EDR data.
- Use 4689 with the same PID to get the exit time and duration of short-lived tools.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1059 Command and Scripting Interpreter | Execution |
| T1059.001 Command and Scripting Interpreter: PowerShell | Execution |
| T1059.003 Command and Scripting Interpreter: Windows Command Shell | Execution |
| T1218 System Binary Proxy Execution | Stealth |
| T1047 Windows Management Instrumentation | Execution |
| T1569.002 System Services: Service Execution | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1182 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 24
- High · 587
- Medium · 512
- Low · 58
- Info · 1
- CriticalDumpStack.log Defender EvasionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - DInjector PowerShell Cradle ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Dumpert Process Dumper ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Empire PowerShell UAC BypassRule by Ecco, SigmaHQ, DRL 1.1
- CriticalHackTool - F-Secure C3 Load by Rundll32Rule by Alfie Champion (ajpc500), SigmaHQ, DRL 1.1
- CriticalHackTool - Inveigh ExecutionRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - PurpleSharp ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Rubeus ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SafetyKatz ExecutionRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SecurityXploded ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SharpUp PrivEsc Tool ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Sliver C2 Implant Activity PatternRule by Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SysmonEOP ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Windows Credential Editor (WCE) ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHacktool Execution - ImphashRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalPersistence Via Sticky Key BackdoorRule by Sreeman, SigmaHQ, DRL 1.1
- CriticalPotential Credential Dumping Via LSASS Process CloneRule by Florian Roth (Nextron Systems), Samir Bousseaden, SigmaHQ, DRL 1.1
- CriticalPotential SMB Relay Attack Tool ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalRenamed Whoami ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalSticky Key Like Backdoor ExecutionRule by Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, SigmaHQ, DRL 1.1
- CriticalSuspicious Child Process Of Veeam DabataseRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalSuspicious PowerShell Mailbox Export to ShareRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalTrustedPath UAC Bypass PatternRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalWMI Backdoor Exchange Transport AgentRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighAADInternals PowerShell Cmdlets Execution - ProccessCreationRule by Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.