Skip to content
Security

Event ID 4658: Object handle closed

The handle to an object was closedSecurity event 4658 marks the closing of a handle to an audited object. Pair it with 4656 by HandleId to measure how long the object was open.
4658
Event ID
4658
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Object access
Default logging
Needs configuration

What event 4658 means

Event 4658 is written when a process closes a handle it previously obtained to an audited file, registry key or kernel object. It carries no object name and no access rights — only the HandleId, the process and the account.

Its value is as a bookend: the matching 4656 (handle requested) and 4663 (access used) share the same HandleId and ProcessId, so the three together tell you what was opened, what was done and for how long. On its own it has little security meaning.

Because every audited handle produces one, 4658 roughly doubles object-access volume. Many teams leave Audit Handle Manipulation off unless they need handle lifetimes.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit Handle Manipulation (Success), in addition to the object subcategory (File System, Registry, Kernel Object or Removable Storage) and a SACL on the object.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that owned the handle.
SubjectLogonIdLogon session of that account.
ObjectServerSubsystem that managed the handle, normally Security.
HandleIdHandle that was closed; match it with 4656 and 4663 from the same process.
ProcessNameProcess that closed the handle.
ProcessIdHexadecimal PID; handle values are only unique within one process.

Common benign sources

  • Every normal open/close cycle on an audited object generates one 4658.
  • Backup, indexing and antivirus software produce long runs of 4656/4658 pairs.

What attackers do that produces it

  • Not an attack indicator by itself. It helps time bulk collection: many handles to sensitive files opened and closed in quick succession by one process.

Investigation tips

  • Use it only as a join partner; filter on the HandleId and ProcessId from an interesting 4656 or 4663.
  • Handle IDs are reused, so correlate in time order and within the same process.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading