Windows Event 4688 + tick the Command Line logging wineventlog : EVAL-parent_process_id parent_process_id Creator_Process_ID wineventlog : EVAL-parent_process_name parent_process_name case(EventCode=="4688", replace(Creator_Process_Name,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")) wineventlog : EVAL-parent_process_path parent_process_path Creator_Process_Name wineventlog : EVAL-process_command_line process_command_line Process_Command_Line wineventlog : EVAL-process_id process_id New_Process_ID wineventlog : EVAL-process_name process_name case(EventCode=="4688",replace(New_Process_Name,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)",""),1==1,"") wineventlog : EVAL-process_path process_path case(EventCode=="4688",New_Process_Name)
... View more