Skip to content
arrow_back
search
E8-AH-ML2.12 bolt ASD Essential Eight

Command line process creation logging is centralized

Log all command line processes in a central location for monitoring.

record_voice_over

Plain language

This control is all about making sure that whenever something runs on a computer using a command line, a record of that action is saved in a central place. This is important because if something harmful were to happen, like a cyberattack or a virus, having these records helps us understand what's going on and how to fix it quickly.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Command line process creation events are centrally logged.
bolt ASD Essential Eight E8-AH-ML2.12
priority_high

Why it matters

Without centralised logging of command line process creation events, attacker-launched tools and scripts may not be detected or investigated in time.

settings

Operational notes

Enable command line process creation logging on endpoints/servers and forward events to a central SIEM; validate coverage, retention and integrity (e.g. hashing) regularly.

Mapping detail

Mapping

Direction

Controls