Files
windows-itpro-docs/windows/security/threat-protection/auditing/audit-process-termination.md
Paolo Matarazzo d6cd44eb56 (Windows 10)
2023-05-24 11:44:39 -04:00

4.2 KiB
Raw Blame History

title, description, ms.assetid, ms.reviewer, manager, ms.author, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, ms.localizationpriority, author, ms.date, ms.technology, ms.topic
title description ms.assetid ms.reviewer manager ms.author ms.pagetype ms.prod ms.mktglfcycl ms.sitesec ms.localizationpriority author ms.date ms.technology ms.topic
Audit Process Termination The Advanced Security Audit policy setting, Audit Process Termination, determines if audit events are generated when an attempt is made to end a process. 65d88e53-14aa-48a4-812b-557cebbf9e50 aaroncz vinpa security windows-client deploy library none vinaypamnani-msft 09/06/2021 itpro-security reference

Audit Process Termination

Audit Process Termination determines whether the operating system generates audit events when process has exited.

Success audits record successful attempts and Failure audits record unsuccessful attempts.

This policy setting can help you track user activity and understand how the computer is used.

Event volume: Low to Medium, depending on system usage.

Computer Type General Success General Failure Stronger Success Stronger Failure Comments
Domain Controller No No IF No IF - This subcategory typically is not as important as Audit Process Creation subcategory. Using this subcategory you can, for example get information about for how long process was run in correlation with 4688 event.
If you have a list of critical processes that run on some computers, you can enable this subcategory to monitor for termination of these critical processes.
This subcategory doesnt have Failure events, so there is no recommendation to enable Failure auditing for this subcategory.
Member Server No No IF No IF - This subcategory typically is not as important as Audit Process Creation subcategory. Using this subcategory you can, for example get information about for how long process was run in correlation with 4688 event.
If you have a list of critical processes that run on some computers, you can enable this subcategory to monitor for termination of these critical processes.
This subcategory doesnt have Failure events, so there is no recommendation to enable Failure auditing for this subcategory.
Workstation No No IF No IF - This subcategory typically is not as important as Audit Process Creation subcategory. Using this subcategory you can, for example get information about for how long process was run in correlation with 4688 event.
If you have a list of critical processes that run on some computers, you can enable this subcategory to monitor for termination of these critical processes.
This subcategory doesnt have Failure events, so there is no recommendation to enable Failure auditing for this subcategory.

Events List:

  • 4689(S): A process has exited.