// REFERENCE

4688 — A new process was created

Log: Security High risk

A process was created. With command-line auditing enabled, the Process Command Line field is hunting gold: it catches LOLBins (certutil, mshta, rundll32), obfuscated PowerShell and anomalous parent-child chains (e.g. Word spawning cmd).

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.