Event Id | 4661 |
Source | Microsoft-Windows-Security-Auditing |
Description | A handle to an object was requested. Subject : Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain name> Logon ID:<Logon ID> Object: Object Server:<Object Server> Object Type:<Object Type> Object Name:<Object Name> Handle ID:<Handle ID> Process Information: Process ID:<Process ID>   Process Name:<Process Name>   Access Request Information: Transaction ID:<Transaction ID> |
Event Information | Cause : This event is logged by multiple subcategories .Some AD objects also double as SAM objects and some properties of those objects double as SAM attributes. This event is logged when opening such SAM objects such as SAM_DOMAIN or SAM_USER. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.