Skip to content
Security

Event ID 4656: Object handle requested

A handle to an object was requestedSecurity event 4656 logs a request for a handle to an audited file, registry key or kernel object, with the access asked for and whether it was granted.
4656
Event ID
4656
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Object access
Default logging
Needs configuration

What event 4656 means

Event 4656 is written when a process asks for a handle to an object whose SACL audits the requested access: a file or folder, a registry key, a kernel object such as a process, or a file on removable storage. A Success record means the handle was granted; a Failure record means access was denied, which makes 4656 the only object-access event that shows refused attempts.

A granted handle proves intent, not action. The record lists what was requested (AccessList, AccessMask), while 4663 shows which rights were actually used. HandleId together with ProcessId ties 4656 to the matching 4663, 4660 (delete) and 4658 (handle closed).

Nothing is logged unless both conditions are met: the matching Object Access subcategory is enabled and the object carries an auditing ACE. Broad SACLs on busy folders produce very high volume.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit File System, Audit Registry, Audit Kernel Object or Audit Removable Storage (Success and/or Failure), plus a SACL on the object that audits the requested access.

Failure auditing of these subcategories can be noisy because applications routinely probe for access they do not get. Pair Success 4656 with 4663 to see what was really done.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that requested the handle.
SubjectLogonIdLogon session of the requester; pivot to 4624 to learn how and from where it logged on.
ObjectServerSubsystem that handled the request, normally Security.
ObjectTypeType of object, e.g. File, Key (registry) or Process.
ObjectNameFull name of the object: file path, registry path in the \REGISTRY\MACHINE\... form, or device path of a process image.
HandleIdHandle value; correlate with 4663, 4660 and 4658 from the same ProcessId.
AccessListRequested rights as message codes, e.g. %%4416 ReadData, %%4417 WriteData, %%1537 DELETE. See event 4663 for the full table.
AccessMaskHexadecimal mask of the requested rights (same bit values as in 4663).
AccessReasonWhich ACE or privilege granted or denied each requested right, when available.
PrivilegeListPrivileges used to obtain the access, such as SeBackupPrivilege, or -.
ProcessNameFull path of the process that requested the handle.
ProcessIdHexadecimal PID of the requesting process.

Common benign sources

  • Backup and antivirus software opening large numbers of audited files.
  • Applications probing a protected file or key and receiving Failure records they handle silently.
  • System processes opening audited registry keys during boot and policy refresh.

What attackers do that produces it

  • Credential theft tools requesting a handle to lsass.exe (ObjectType Process) when Audit Kernel Object is enabled and the process carries an auditing ACE.
  • Repeated Failure 4656 records for sensitive files or shares from one account, showing someone probing for access.
  • Handles requested with SeBackupPrivilege by a user account to read files it has no direct rights to.

Investigation tips

  • Separate Success from Failure first; failures show attempts, successes need a 4663 to prove use.
  • Join on HandleId and ProcessId to follow the handle through 4663, 4660 and 4658.
  • Review ProcessName against the object: an unexpected binary opening sensitive files or the LSASS process is more telling than the account name.
  • Pivot SubjectLogonId to 4624 to see the logon type and source of the session.

MITRE ATT&CK techniques

TechniqueTactics
T1003.001 OS Credential Dumping: LSASS MemoryCredential Access
T1005 Data from Local SystemCollection

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

12 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Critical · 1
  • High · 3
  • Medium · 8

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading