Windows EventInformation
Windows Event ID 4696 – Microsoft-Windows-Security-Auditing: Primary Token Assigned to Process
Event ID 4696 records when Windows assigns a primary token to a new process during creation, providing detailed security context for process auditing and forensic analysis.