Event ID: 4608

Windows is starting up

Windows is starting up.

This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Microsoft Documentation

Event ID - 4608



This event is logged when LSASS.EXE process starts and the auditing subsystem is initialized.

It typically generates during operating system startup process.



Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Security State Change"
How to enable Windows Auditing



LEFT/RIGHT arrow keys for navigation

Back to List