Skip to content
Security

Event ID 4689: Process exited

A process has exitedSecurity event 4689 logs a process exit with its PID, path, account and exit code. Pair it with 4688 to get how long a process ran. Off by default.
4689
Event ID
4689
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Processes
Default logging
Needs configuration

What event 4689 means

Event 4689 is the counterpart of 4688: it is written when a process terminates, with the process path (ProcessName), its PID (ProcessId), the account and logon session, and the exit code (Status).

On its own it adds little, but joined with the matching 4688 it gives the lifetime of a process. Attacker tools are often short-lived — a credential dumper or a discovery command that runs for a second — and a creation/exit pair a few hundred milliseconds apart is typical of scripted activity.

It is also the way to notice that a process which should always run has stopped, such as a security agent killed shortly before an intrusion continues.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Detailed Tracking > Audit Process Termination (Success). Not enabled in the default audit policy.

Roughly doubles the volume of process auditing; many environments enable 4688 but not 4689.

Key fields

FieldWhat it tells you
SubjectUserNameAccount the process ran as.
SubjectLogonIdLogon session of the process; matches SubjectLogonId (or TargetLogonId) of the 4688.
ProcessIdHexadecimal PID of the exited process — matches NewProcessId in 4688. Use the timestamp too, as PIDs are reused.
ProcessNameFull path of the exited executable.
StatusExit code in hexadecimal. 0x0 usually means success; other values are application-specific, so only compare them within the same program.

Common benign sources

  • Every normal process exit — the event is as frequent as 4688.
  • Short-lived helpers (conhost.exe, updaters, installers) that start and stop within seconds.

What attackers do that produces it

  • Security or monitoring agents (EDR, antivirus, Sysmon) exiting unexpectedly, especially right after an administrator session starts.
  • Short bursts of tools that run and exit in under a second, typical of scripted discovery or credential dumping.

Investigation tips

  • Join 4688 and 4689 on PID and host within a time window to compute process duration and spot very short or very long-running unusual processes.
  • For an agent that stopped, check which session was active at that moment (SubjectLogonId, 4624) and whether a 4688 of taskkill, sc or similar preceded it.

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading