EventID 9707: Command Execution Started
Last updated
Last updated
This event indicates that a logon task defined in Run/RunOnce Registry Keys has executed.
Windows 11
✅
Server 2019
✅
Windows 10
✅
Server 2016
✅
Windows 8
✅
Server 2012
✅
Windows 7
✅
Server 2008
✅
Windows Vista
✅
Server 2003
❌
Windows XP
❌
%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx
System/Security/UserID
This field provides the SID of the account that the logon task executed under.
EventData/Command
This field shows the full command line options of the task that was run.
System/Execution/ProcessID
This field provides the process ID that the task ran with.
System/Execution/ThreadID
This field provides the thread ID that the task ran with.
On an example system, the following registry key exists:
During a user logon, the following Microsoft-Windows-Shell-Core/Operational/9707
event is logged:
This example was produced on Windows 10, Version 10.0.19044 Build 19044