// REFERENCE
4688 — A new process was created
Log: Security
High risk
A process was created. With command-line auditing enabled, the Process Command Line field is hunting gold: it catches LOLBins (certutil, mshta, rundll32), obfuscated PowerShell and anomalous parent-child chains (e.g. Word spawning cmd).
Related tools
Work with this in:
Related
4672
4672 — Special privileges assigned to new logon 4673
4673 — Sensitive privilege use 4689
4689 — A process has exited
4672 — Special privileges assigned to new logon 4673
4673 — Sensitive privilege use 4689
4689 — A process has exited
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.