Ensure Audit Success for 'Audit Policy: Detailed Tracking: Process Creation'
|ID: oval:org.secpod.oval:def:35502||Date: (C)2016-06-10 (M)2017-10-23|
|Class: COMPLIANCE||Family: windows|
This subcategory reports the creation of a process and the name of the program or user that created it.
Note: These events now get audited earlier than in previous versions of Windows. The creation of smss.exe and other early processes is now audited. Default settings that cannot be altered until after Lsass starts.
Events for this subcategory include:
- 4688: A new process has been created.
- 4696: A primary token was assigned to process.
Refer to the Microsoft Knowledgebase article 'Description of security events in Windows Vista and in Windows Server 2008' for the most recent information about this setting: http://support.microsoft.com/kb/947226.
|Microsoft Windows 10|