// REFERENCE

Sysmon 1 — Process creation

Log: Sysmon/Operational High risk

Process creation logged by Sysmon, richer than 4688: it includes CommandLine, ParentImage, Hashes and OriginalFileName. It's the backbone of most endpoint hunting: anomalous parent-child chains, LOLBins and renamed binaries.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.