Event ID 4608
Windows is starting upWindows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
This event is logged when LSASS.EXE process starts and the auditing subsystem is initialized.
It typically generates during operating system startup process.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Security State Change"
LEFT/RIGHT arrow keys for navigation
Back to List