Event ID 4658
The handle to an object was closedThe handle to an object was closed. Subject : Security ID: %1 Account Name: %2 Account Domain: %3 Logon ID: %4 Object: Object Server: %5 Handle ID: %6 Process Information: Process ID: %7 Process Name: %8
Auditing:
It's not recommended to audit the "Kernel Object" subcategory.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /category:"Object Access"
Operating Systems:
Windows Vista Windows 2008 Windows 7 Windows 2008 R2 Windows 8 Windows 2012 Windows 8.1 Windows 2012 R2 Windows 10 Windows 2016 Windows 2019 Windows 2022Tags:
Audit SuccessAudit Category:
Object AccessAudit Subcategory:
File System Handle Manipulation Kernel Object Registry Removable StorageLEFT/RIGHT arrow keys for navigation
Back to List