EventID 9707: Command Execution Started

This event indicates that a logon task defined in Run/RunOnce Registry Keys has executed.

Analysis Value

Security Identifierchevron-rightCommand Line Optionschevron-rightExecution Accountchevron-rightParent and Child Informationchevron-rightEvidence of Executionchevron-rightExecution Timestampchevron-right

Operating System Availability

Major Version
Support
Major Version
Support

Windows 11

βœ…

Server 2019

βœ…

Windows 10

βœ…

Server 2016

βœ…

Windows 8

βœ…

Server 2012

βœ…

Windows 7

βœ…

Server 2008

βœ…

Windows Vista

βœ…

Server 2003

❌

Windows XP

❌

Artifact Location(s)

  • %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx

Artifact Interpretation

Field
Interpretation
Reference

System/Security/UserID

This field provides the SID of the account that the logon task executed under.

EventData/Command

This field shows the full command line options of the task that was run.

System/Execution/ProcessID

This field provides the process ID that the task ran with.

System/Execution/ThreadID

This field provides the thread ID that the task ran with.

circle-info

The timestamp of the event indicates the time at which the task was executed.

Example

On an example system, the following registry key exists:

During a user logon, the following Microsoft-Windows-Shell-Core/Operational/9707 event is logged:

This example was produced on Windows 10, Version 10.0.19044 Build 19044

Last updated