Event Id | 4907 |
Source | Microsoft-Windows-Security-Auditing |
Description | Auditing settings on object were changed. Subject: Security ID:<Security ID> Account Name: <Account Name> Account Domain:<Domain Name> Logon ID:<Logon ID> Object: Object Server: <Object Server> Object Type: <Object Type> Object Name: <Object Name> Handle ID: <Handle ID> Process Information: Process ID: <Process ID> Process Name: <Process Name> Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;OIIOSAFA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) |
Event Information | Cause : When user change the audit SACL of an object, such as a file or folder, Windows logs this event. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.