Event ID 4659

A handle to an object was requested with intent to delete

A handle to an object was requested with intent to delete.

Subject:
    Security ID:        %1
    Account Name:       %2
    Account Domain:     %3
    Logon ID:           %4

Object:
    Object Server:      %5
    Object Type:        %6
    Object Name:        %7
    Handle ID:          %8

Process Information:
    Process ID:         %13

Access Request Information:
    Transaction ID:     %9
    Accesses:           %10
    Access Mask:        %11
    Privileges Used for Access Check:   %12


This event is often logged instead of a 4663 event when a file is deleted.

This event also appears to be logged when a file that is currently locked by a process (or Windows) is attempted to be deleted.



NameFieldInsertion StringOSExample
Security IDSubjectUserSid%1Any THEDOMAIN\TheUser
Account NameSubjectUserName%2Any TheUser
Account DomainSubjectDomainName%3Any THEDOMAIN
Logon IDSubjectLogonId%4Any 0x5f2ac745
Object ServerObjectServer%5Any Security
Object TypeObjectType%6Any File
Object NameObjectName%7Any C:\Shares\Marketing\~secretplan.xlsx
Handle IDHandleId%8Any 0x0
Transaction IDTransactionIdf%9Any {00000000-0000-0000-0000-000000000000}
AccessesAccessList%10Any -
Access MaskAccessMask%11Any 0x0
Privileges Used for Access CheckPrivilegeList%12Any -
ProcessIDProcessId%13Any 0x4


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"File System"



LEFT/RIGHT arrow keys for navigation

Back to List