Event ID 4689: Process exited
- Event ID
- 4689
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 4689 means
Event 4689 is the counterpart of 4688: it is written when a process terminates, with the process path (ProcessName), its PID (ProcessId), the account and logon session, and the exit code (Status).
On its own it adds little, but joined with the matching 4688 it gives the lifetime of a process. Attacker tools are often short-lived — a credential dumper or a discovery command that runs for a second — and a creation/exit pair a few hundred milliseconds apart is typical of scripted activity.
It is also the way to notice that a process which should always run has stopped, such as a security agent killed shortly before an intrusion continues.
When it is logged
Advanced Audit Policy Configuration > Detailed Tracking > Audit Process Termination (Success). Not enabled in the default audit policy.
Roughly doubles the volume of process auditing; many environments enable 4688 but not 4689.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account the process ran as. |
| SubjectLogonId | Logon session of the process; matches SubjectLogonId (or TargetLogonId) of the 4688. |
| ProcessId | Hexadecimal PID of the exited process — matches NewProcessId in 4688. Use the timestamp too, as PIDs are reused. |
| ProcessName | Full path of the exited executable. |
| Status | Exit code in hexadecimal. 0x0 usually means success; other values are application-specific, so only compare them within the same program. |
Common benign sources
- Every normal process exit — the event is as frequent as 4688.
- Short-lived helpers (
conhost.exe, updaters, installers) that start and stop within seconds.
What attackers do that produces it
- Security or monitoring agents (EDR, antivirus, Sysmon) exiting unexpectedly, especially right after an administrator session starts.
- Short bursts of tools that run and exit in under a second, typical of scripted discovery or credential dumping.
Investigation tips
- Join 4688 and 4689 on PID and host within a time window to compute process duration and spot very short or very long-running unusual processes.
- For an agent that stopped, check which session was active at that moment (SubjectLogonId, 4624) and whether a 4688 of
taskkill,scor similar preceded it.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.