Microsoft-Windows-Security-Auditing › Event 4688

Event ID 4688 — A new process has been created.

Provider
Microsoft-Windows-Security-Auditing
Channel
Security
Audit Policy
Detailed Tracking → Process Creation
Collection Priority
Recommended (Yamato Security, others)
Opcode
Info

Description

A new process has been created.

Message #

A new process has been created.

Subject:
	Security ID: %1
	Account Name: %2
	Account Domain: %3
	Logon ID: %4

Process Information:
	New Process ID: %5
	New Process Name: %6
	Token Elevation Type: %7
	Creator Process ID: %8

Token Elevation Type indicates the type of token that was assigned to the new process in accordance with User Account Control policy.

Type 1 is a full token with no privileges removed or groups disabled.  A full token is only used if User Account Control is disabled or if the user is the built-in Administrator account or a service account.

Type 2 is an elevated token with no privileges removed or groups disabled.  An elevated token is used when User Account Control is enabled and the user chooses to start the program using Run as administrator.  An elevated token is also used when an application is configured to always require administrative privilege or to always require maximum privilege, and the user is a member of the Administrators group.

Type 3 is a limited token with administrative privileges removed and administrative groups disabled.  The limited token is used when User Account Control is enabled, the application does not require administrative privilege, and the user does not choose to start the program using Run as administrator.

Fields #

NameDescription
SubjectUserSid SID[Creator Subject] Security ID.
SubjectUserName UnicodeString[Creator Subject] Account Name.
SubjectDomainName UnicodeString[Creator Subject] Account Domain.
SubjectLogonId HexInt64[Creator Subject] Logon ID.
NewProcessId Pointer[Process Information] New Process ID.
NewProcessName UnicodeString[Process Information] New Process Name.
TokenElevationType UnicodeString[Process Information] Token Elevation Type.
Known values
%%1936
TokenElevationTypeDefault (1)
%%1937
TokenElevationTypeFull (2)
%%1938
TokenElevationTypeLimited (3)
1
TokenElevationTypeDefault
2
TokenElevationTypeFull
3
TokenElevationTypeLimited
ProcessId Pointer[Process Information] Creator Process ID.
CommandLine UnicodeString[Process Information] Process Command Line.
TargetUserSid SID[Target Subject] Security ID.
TargetUserName UnicodeString[Target Subject] Account Name.
TargetDomainName UnicodeString[Target Subject] Account Domain.
TargetLogonId HexInt64[Target Subject] Logon ID.
ParentProcessName UnicodeString[Process Information] Creator Process Name.
MandatoryLabel SID[Process Information] Mandatory Label.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Auditing",
    "guid": "54849625-5478-4994-A5BA-3E3B0328C30D",
    "event_source_name": "",
    "event_id": 4688,
    "version": 2,
    "level": 0,
    "task": 13312,
    "opcode": 0,
    "keywords": 9232379236109516800,
    "time_created": "2023-11-06T06:25:27.153945+00:00",
    "event_record_id": 2753,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 336
    },
    "channel": "Security",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "SubjectUserSid": "S-1-5-18",
    "SubjectUserName": "-",
    "SubjectDomainName": "-",
    "SubjectLogonId": "0x3e7",
    "NewProcessId": "0x328",
    "NewProcessName": "C:\\Windows\\System32\\lsass.exe",
    "TokenElevationType": "%%1936",
    "ProcessId": "0x27c",
    "CommandLine": "",
    "TargetUserSid": "S-1-0-0",
    "TargetUserName": "-",
    "TargetDomainName": "-",
    "TargetLogonId": "0x0",
    "ParentProcessName": "C:\\Windows\\System32\\wininit.exe",
    "MandatoryLabel": "S-1-16-16384"
  },
  "message": ""
}

Detection Patterns #

429 rules

Sigma

Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Show 411 more (414 total)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Andreas Hunkeler (@Karneades), Markus Neis
Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Roberto Rodriguez @Cyb3rWard0g
Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems)
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
frack113, Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community
Victor Sergeev, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Markus Neis, Nasreddine Bencherchali (Nextron Systems)
Markus Neis, Nasreddine Bencherchali (Nextron Systems)
Moriarty Meng (idea), Anton Kutepov (rule), oscd.community
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Jonathan Cheong, oscd.community
Daniel Bohannon (@Mandiant/@FireEye), oscd.community
Jonathan Cheong, oscd.community
Jonathan Cheong, oscd.community
Timur Zinniatullin, oscd.community
Nikita Nazarov, oscd.community
Nikita Nazarov, oscd.community
Nikita Nazarov, oscd.community
Julia Fomina, oscd.community
Florian Roth (Nextron Systems)
Christian Burkard (Nextron Systems), pH-T (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix)
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community
Swachchhanda Shrawan Poudel (Nextron Systems)
Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)
Max Altgelt (Nextron Systems)
Swachchhanda Shrawan Poudel (Nextron Systems)
Swachchhanda Shrawan Poudel
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Michael Haag, Florian Roth (Nextron Systems), Markus Neis, Elastic, FPT.EagleEye Team
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems)
0xFustang, Swachchhanda Shrawan Poudel (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Tom Ueltschi (@c_APT_ure), Tim Shelton
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Aedan Russell, frack113, X__Junior (Nextron Systems)
Aedan Russell, frack113, X__Junior (Nextron Systems)
Florian Roth (Nextron Systems), MSTI (query)
Florian Roth (Nextron Systems)
Cian Heasley, Florian Roth (Nextron Systems)
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
Ivan Dyachkov, Yulia Fomina, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Christian Burkard (Nextron Systems)
Christian Burkard (Nextron Systems)
Christian Burkard (Nextron Systems)
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community
Christian Burkard (Nextron Systems)
Christian Burkard (Nextron Systems)
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Florian Roth (Nextron Systems)
Christian Burkard (Nextron Systems)
Florian Roth (Nextron Systems)
Ensar Şamil, @sblmsrsn, @oscd_initiative
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @gott_cyber
Florian Roth (Nextron Systems)
juju4, Jonhnathan Ribeiro, oscd.community
Florian Roth (Nextron Systems), Tim Shelton
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
David Burkett, @signalblur
Swachchhanda Shrawan Poudel (Nextron Systems)
@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community
Konstantin Grishchenko, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Teymur Kheirkhabarov, Ecco, Florian Roth
Florian Roth (Nextron Systems)
@gott_cyber, Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Swachchhanda Shrawan Poudel (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova
frack113, Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, frack113
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri)
andrewdanis, Swachchhanda Shrawan Poudel (Nextron Systems)
Josh Nickels, mttaggart
Sreeman, Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Bhabesh Raj, X__Junior (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Beyu Denis, oscd.community (rule), @_felamos (idea)
Beyu Denis, oscd.community
Beyu Denis, oscd.community (rule), @harr0ey (idea)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Ensar Şamil, @sblmsrsn, @oscd_initiative
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel
Nasreddine Bencherchali (Nextron Systems), Karneades / Markus Neis, Jonhnathan Ribeiro, oscd.community
Nasreddine Bencherchali (Nextron Systems), Karneades / Markus Neis, Jonhnathan Ribeiro, oscd.community
Austin Songer (@austinsonger)
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel
Agro (@agro_sev), Ensar Şamil (@sblmsrsn), oscd.community
Maxime Thiebaut (@0xThiebaut)
Ensar Şamil, @sblmsrsn, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Timur Zinniatullin, oscd.community
Swachchhanda Shrawan Poudel
Nasreddine Bencherchali (Nextron Systems)
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), John Lambert (idea), elhoim
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Ilya Krestinichev, Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Sreeman, Florian Roth (Nextron Systems)
Sergey Soldatov, Kaspersky Lab, oscd.community
Nasreddine Bencherchali (Nextron Systems), Scoubi (@ScoubiMtl)
frack113, Nasreddine Bencherchali (Nextron Systems)
frack113, Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems), Samir Bousseaden
Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton
Kirill Kiryanov, oscd.community
E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Teymur Kheirkhabarov, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Furkan Caliskan (@caliskanfurkan_)
Swachchhanda Shrawan Poudel (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems), kagebunsher
Swachchhanda Shrawan Poudel (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Swachchhanda Shrawan Poudel (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'
Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Nikita Nazarov, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea)
Karneades, Swisscom CSIRT
@Kostastsale, Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems)
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Timur Zinniatullin, E.M. Anhaus, oscd.community
Daniil Yugoslavskiy, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Swachchhanda Shrawan Poudel (Nextron Systems)
Muhammad Faisal (@faisalusuf)
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Florian Roth (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
Nounou Mbeiri, Swachchhanda Shrawan Poudel (Nextron Systems)
Daniil Yugoslavskiy, Ian Davis, oscd.community
Nasreddine Bencherchali (Nextron Systems)
Nasreddine Bencherchali (Nextron Systems)
frack113, Nasreddine Bencherchali (Nextron Systems), X__Junior
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems)
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems)

Kusto Query Language

Microsoft Security Research
26 rules

Detection Rules #

View all rules referencing this event →

Sigma # view in reference

Show 17 more (55 total)

Elastic # view in reference

  • Potential LSASS Clone Creation via PssCaptureSnapShot source high: Identifies the creation of an LSASS process clone via PssCaptureSnapShot where the parent process is the initial LSASS process instance. This may indicate an attempt to evade detection and dump LSASS memory for credential access.

Kusto Query Language # view in reference

  • SUNBURST suspicious SolarWinds child processes source medium: Identifies suspicious child processes of SolarWinds.Orion.Core.BusinessLayer.dll that may be evidence of the SUNBURST backdoor References: - https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html - https://gist.github.com/olafhartong/71ffdd4cab4b6acd5cbcd1a0691ff82f
  • Unusual identity creation using exchange powershell source high: ' The query below identifies creation of unusual identity by the Europium actor to mimic Microsoft Exchange Health Manager Service account using Exchange PowerShell commands Reference: https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government/'
  • Identify Mango Sandstorm powershell commands source high: 'The query below identifies powershell commands used by the threat actor Mango Sandstorm. Reference: https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations/'
Show 16 more (19 total)

References #