Event Id | 4660 |
Source | Microsoft-Windows-Security-Auditing |
Description | An object was deleted. Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain name> Logon ID:<Logon ID> Object: Object Server:<Object Server> Handle ID:<Handle ID> Process Information: Process ID: <Process ID>   Process Name:<Process Name>   Transaction ID:<Transaction ID>   |
Event Information | Cause : This event is logged when an object is deleted where that object's audit policy has auditing enabled for deletions for the user who just deleted it . Resolution : |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.