Blog | G5 Cyber Security

The most important Windows 10 security event log IDs to monitor

Monitoring Windows 10 event logs is one of the best ways to detect malicious activity on your network. These are the most important types of log events to look for and what they can tell you. Windows security event log ID 4688 documents each program a computer executes, its identifying data, and the process that started it. Event 4688s occur on your system when you log into a system. For example, Session Manager Subsystem (SMSS.exe) launches at login and event 4688 is logged. The logged token elevation type shows what user rights are associated with the program.”]

Source: https://www.csoonline.com/article/3561889/the-most-important-windows-10-security-event-log-ids-to-monitor.html

Exit mobile version