Event ID: 4608Windows is starting up
Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
This event is logged when LSASS.EXE process starts and the auditing subsystem is initialized.
It typically generates during operating system startup process.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Security State Change"
LEFT/RIGHT arrow keys for navigationBack to List