Microsoft recently released an update (KB 3004375) that allows certain versions the Windows OS to record command line options, if Process Tracking is enabled, in the Windows Event Log. Microsoft also recently upgraded Sysmon to version 2.0, with some interesting new capabilities.
more here.............http://windowsir.blogspot.com/2015/02/tools.html
more here.............http://windowsir.blogspot.com/2015/02/tools.html