Skip to content
Security

Event ID 4660: Object deleted

An object was deletedSecurity event 4660 confirms that an audited file, registry key or kernel object was deleted. It has no object name, so join it to 4663 by HandleId.
4660
Event ID
4660
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Object access
Default logging
Needs configuration

What event 4660 means

Event 4660 is written when an object whose SACL audits Delete is actually deleted. Unlike 4663 with the DELETE right, which also appears for renames and moves, 4660 is only produced by a real deletion.

The catch is that 4660 does not contain the object name. It carries the HandleId and ProcessId, and the name comes from the 4663 (or 4656) with the same handle logged just before it. Build the pair and you get a reliable record of who deleted which file and with which process.

On file servers this is the event behind "who deleted the folder" questions, and during incidents it helps spot mass deletion by ransomware or cleanup scripts.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit File System, Audit Registry or Audit Kernel Object (Success), plus a SACL on the object that audits Delete.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that deleted the object.
SubjectLogonIdLogon session of that account; pivot to 4624 for the source.
ObjectServerSubsystem, normally Security.
HandleIdHandle used for the deletion; the matching 4663 with the same value names the object.
ProcessNameProcess that performed the deletion, e.g. explorer.exe or a script host.
ProcessIdHexadecimal PID of that process.
TransactionIdTransaction GUID for transacted operations; all zeros otherwise.

Common benign sources

  • Users deleting their own files through Explorer or applications.
  • Temporary file cleanup by installers, Office and browsers in audited folders.

What attackers do that produces it

  • Mass deletion of files on a share shortly before or after encryption by ransomware.
  • Deleting tools, output files or logs after use to cover tracks.

Investigation tips

  • Join each 4660 to the preceding 4663 with the same HandleId and ProcessId to get ObjectName.
  • Count deletions per account and per process per minute to separate user activity from scripted deletion.
  • For deletions over SMB, correlate with 5145 on the file server to get the client IP.

MITRE ATT&CK techniques

TechniqueTactics
T1070.004 Indicator Removal: File DeletionStealth
T1485 Data DestructionImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading