Process Termination
Enabled by default
Service: Microsoft Windows Security auditing
Log type: Security
Applications being closed is a common thing on a computer but may signal unusual software being closed or give a timeline of events.
Get-WinEvent -FilterHashTable @{LogName='Security';ID='4689'} -MaxEvents 1 | Format-List
auditpol /get /subcategory:"Process Termination"
auditpol /set /subcategory:"Process Termination" /Success:Disable /Failure:Disable
auditpol /set /subcategory:"Process Termination" /Success:Enable /Failure:Enable
Compliance
HIPAA
Level: Recommended
PCI DSS
Level: Recommended
https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf?agreement=true&time=1631643252599
To view the process creation log, navigate to the Windows Event Viewer and the security tab. Next, sort or filter the log by Event ID 4689.
data:image/s3,"s3://crabby-images/3b497/3b49741faaa8e2a77a63ec47f46a7afce9037ece" alt=""
To view this log in the command line with Get-WinEvent, open PowerShell as an administrator. From here, enter the command Get-WinEvent -FilterHashTable @{LogName='Security';ID='4689'} -MaxEvents 1 | Format-List
data:image/s3,"s3://crabby-images/19558/19558ed149fda2ed409fdb507284ffc34c89e39b" alt=""
To view this log in the command line with wevtutil, open PowerShell or Command Prompt as an administrator. From here, enter the commandwevtutil qe Security "/q:*[System [(EventID=4689)]]"
data:image/s3,"s3://crabby-images/18772/18772f9ddb1a43c201470762f5503ec3b85b6883" alt=""