Event ID 4660: Object deleted
- Event ID
- 4660
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Object access
- Default logging
- Needs configuration
What event 4660 means
Event 4660 is written when an object whose SACL audits Delete is actually deleted. Unlike 4663 with the DELETE right, which also appears for renames and moves, 4660 is only produced by a real deletion.
The catch is that 4660 does not contain the object name. It carries the HandleId and ProcessId, and the name comes from the 4663 (or 4656) with the same handle logged just before it. Build the pair and you get a reliable record of who deleted which file and with which process.
On file servers this is the event behind "who deleted the folder" questions, and during incidents it helps spot mass deletion by ransomware or cleanup scripts.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit File System, Audit Registry or Audit Kernel Object (Success), plus a SACL on the object that audits Delete.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that deleted the object. |
| SubjectLogonId | Logon session of that account; pivot to 4624 for the source. |
| ObjectServer | Subsystem, normally Security. |
| HandleId | Handle used for the deletion; the matching 4663 with the same value names the object. |
| ProcessName | Process that performed the deletion, e.g. explorer.exe or a script host. |
| ProcessId | Hexadecimal PID of that process. |
| TransactionId | Transaction GUID for transacted operations; all zeros otherwise. |
Common benign sources
- Users deleting their own files through Explorer or applications.
- Temporary file cleanup by installers, Office and browsers in audited folders.
What attackers do that produces it
- Mass deletion of files on a share shortly before or after encryption by ransomware.
- Deleting tools, output files or logs after use to cover tracks.
Investigation tips
- Join each 4660 to the preceding 4663 with the same
HandleIdandProcessIdto getObjectName. - Count deletions per account and per process per minute to separate user activity from scripted deletion.
- For deletions over SMB, correlate with 5145 on the file server to get the client IP.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.