Event Id | 4659 |
Source | Microsoft-Windows-Security-Auditing |
Description | A handle to an object was requested with intent to delete. Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain name> Logon ID:<Logon ID> Object: Object Server:<Object Server> Object Type:<Object Type> Object Name:<Object Name> Handle ID:<Handle ID> Process Information: Process ID: <Process ID>   Access Request Information: Transaction ID:<Transaction ID>   Accesses: <Accesses>   Access Mask:<Access Mask>   Privileges Used for Access Check: |
Event Information | Cause : This event should be logged whenever user install a patch that requires replacement of a file that is already opened by Windows and can't be closed until shut down. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.