Event ID 4656: Object handle requested
- Event ID
- 4656
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Object access
- Default logging
- Needs configuration
What event 4656 means
Event 4656 is written when a process asks for a handle to an object whose SACL audits the requested access: a file or folder, a registry key, a kernel object such as a process, or a file on removable storage. A Success record means the handle was granted; a Failure record means access was denied, which makes 4656 the only object-access event that shows refused attempts.
A granted handle proves intent, not action. The record lists what was requested (AccessList, AccessMask), while 4663 shows which rights were actually used. HandleId together with ProcessId ties 4656 to the matching 4663, 4660 (delete) and 4658 (handle closed).
Nothing is logged unless both conditions are met: the matching Object Access subcategory is enabled and the object carries an auditing ACE. Broad SACLs on busy folders produce very high volume.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit File System, Audit Registry, Audit Kernel Object or Audit Removable Storage (Success and/or Failure), plus a SACL on the object that audits the requested access.
Failure auditing of these subcategories can be noisy because applications routinely probe for access they do not get. Pair Success 4656 with 4663 to see what was really done.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that requested the handle. |
| SubjectLogonId | Logon session of the requester; pivot to 4624 to learn how and from where it logged on. |
| ObjectServer | Subsystem that handled the request, normally Security. |
| ObjectType | Type of object, e.g. File, Key (registry) or Process. |
| ObjectName | Full name of the object: file path, registry path in the \REGISTRY\MACHINE\... form, or device path of a process image. |
| HandleId | Handle value; correlate with 4663, 4660 and 4658 from the same ProcessId. |
| AccessList | Requested rights as message codes, e.g. %%4416 ReadData, %%4417 WriteData, %%1537 DELETE. See event 4663 for the full table. |
| AccessMask | Hexadecimal mask of the requested rights (same bit values as in 4663). |
| AccessReason | Which ACE or privilege granted or denied each requested right, when available. |
| PrivilegeList | Privileges used to obtain the access, such as SeBackupPrivilege, or -. |
| ProcessName | Full path of the process that requested the handle. |
| ProcessId | Hexadecimal PID of the requesting process. |
Common benign sources
- Backup and antivirus software opening large numbers of audited files.
- Applications probing a protected file or key and receiving Failure records they handle silently.
- System processes opening audited registry keys during boot and policy refresh.
What attackers do that produces it
- Credential theft tools requesting a handle to
lsass.exe(ObjectTypeProcess) when Audit Kernel Object is enabled and the process carries an auditing ACE. - Repeated Failure 4656 records for sensitive files or shares from one account, showing someone probing for access.
- Handles requested with
SeBackupPrivilegeby a user account to read files it has no direct rights to.
Investigation tips
- Separate Success from Failure first; failures show attempts, successes need a 4663 to prove use.
- Join on
HandleIdandProcessIdto follow the handle through 4663, 4660 and 4658. - Review
ProcessNameagainst the object: an unexpected binary opening sensitive files or the LSASS process is more telling than the account name. - Pivot
SubjectLogonIdto 4624 to see the logon type and source of the session.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
12 SigmaHQ detection rules (release r2026-07-01) target this event.
- Critical · 1
- High · 3
- Medium · 8
- CriticalWCE wceaux.dll AccessRule by Thomas Patzke, SigmaHQ, DRL 1.1
- HighPassword Dumper Activity on LSASSRule by sigma, SigmaHQ, DRL 1.1
- HighSAM Registry Hive Handle RequestRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- HighSysKey Registry Keys AccessRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumAzure AD Health Monitoring Agent Registry Keys AccessRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, SigmaHQ, DRL 1.1
- MediumAzure AD Health Service Agents Registry Keys AccessRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, SigmaHQ, DRL 1.1
- MediumLSASS Access From Non System AccountRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumPotential Secure Deletion with SDeleteRule by Thomas Patzke, SigmaHQ, DRL 1.1
- MediumPotentially Suspicious AccessMask Requested From LSASSRule by Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update), SigmaHQ, DRL 1.1
- MediumProcesses Accessing the Microphone and WebcamRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumSCM Database Handle FailureRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumWindows Defender Exclusion Registry Key - Write Access RequestedRule by @BarryShooshooga, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.