Process Creation Events (4688)
Also called Event ID 4688, process creation auditing, command line logging, Sysmon Event ID 1.
- PLATFORM
- Windows
- CATEGORY
- Program Execution
- INDEX
- 17 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
A Security log record written each time a process starts, naming the account, the executable, the parent process and — if separately enabled — the full command line.
Where it lives
Security event log, Event ID 4688; the richer equivalent is Sysmon Event ID 1 in Microsoft-Windows-Sysmon/Operational where Sysmon is deployed
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of process creation events (4688)” is neither.
What it records
When process creation auditing is enabled, Windows writes an event naming the subject account and SID, the new process identifier and image path, the creating process, and the token elevation type. Inclusion of the command line is governed by a separate policy setting and is off by default, which is significant because the command line is usually where the evidence is. Sysmon Event ID 1, where deployed, adds file hashes, the original file name from the binary's metadata, and a parent process command line.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a named executable started under a named account at a recorded time, with the parent process that launched it
- The full command line, where command-line auditing was enabled — arguments, target paths, destination hosts, and switches such as those that suppress confirmation prompts
- Process ancestry, which distinguishes a program the user launched from one spawned by a script or by a remote-execution mechanism
- Token elevation, showing whether the process ran with administrative rights
- A hash of the executable and its original file name, where Sysmon supplied the record
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- Anything at all where auditing was not enabled. Process creation auditing is off by default on Windows, and command-line capture is a further setting that is off even when process auditing is on — the most common finding in this area is that nothing was recorded
- That the account named is the person. The event records the security context, and a service account, a scheduled task, or a remote session under stolen credentials produces the same field
- What the process did. The event marks the start; effects come from other artifacts
- Activity older than the log's rollover. The Security log is size-capped and on a busy server can hold hours rather than weeks
- That an absent event means the process did not run. Log clearing, rollover and disabled auditing are indistinguishable in the resulting silence
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Establishing that command-line auditing was off, which reduces the event to a bare image path and removes most of its evidentiary value
- Showing the Security log rolled over during the period at issue, or that its maximum size made meaningful retention impossible
- Attacking the account-to-person link, particularly where the process was created in a remote session or under a shared administrative account
- Arguing that Sysmon configuration excluded the activity in question, since its capture is governed by a rule set the party controls
What survives, and for how long
Events live in the Security event log until it reaches its configured maximum size and rolls, which on a domain controller or busy server is frequently a matter of hours. Forwarding to a collector or SIEM is what turns this from a short window into usable evidence, and whether that forwarding existed is a question to ask in the first discovery conference.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Does Windows log every program that runs?
No. Process creation auditing, which produces Event ID 4688, is off by default. Even where it has been enabled, capture of the command line is a separate setting that is also off by default — and the command line is normally where the evidence is. On most workstations examined in civil litigation there is no process creation log at all for the period in dispute.
What does Event ID 4688 contain?
It names the account and SID under which the process started, the new process identifier and its image path, the process that created it, and the token elevation type. Where command-line auditing was separately enabled it also carries the full command line, including arguments and target paths. Process ancestry is often the most useful field, because it distinguishes a user launch from a scripted or remote one.
Is Sysmon better than 4688 for process evidence?
It records more, which is not the same as being better evidence. Sysmon Event ID 1 adds file hashes, the binary's original file name, and the parent command line — material that identifies exactly which build ran. But its capture is governed by a configuration file the party controls, so an absence has to be checked against the rule set in force rather than treated as an absence of activity.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Prefetch
Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.
Windows Logon Events (4624 and 4625)
Security log records of each logon and failed logon attempt, naming the account, the logon type, the source workstation and address, and the resulting session identifier.
EDR Telemetry
Security-agent telemetry recording process execution with command lines and hashes, file operations, and outbound network connections — the richest endpoint record available, retained on the vendor's terms.
Microsoft Defender Logs
Antivirus detection and scan records that name file paths, detected tool families, process images, and changes to protection settings such as newly added scan exclusions.
Whether the process creation events (4688)evidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.