Skip to content
Security

Event ID 4663: Object access

An attempt was made to access an objectSecurity event 4663 records an access right actually used on an audited file, folder, registry key or kernel object: who, which process, and what access.
4663
Event ID
4663
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Object access
Default logging
Needs configuration

What event 4663 means

Event 4663 is written when a process uses an access right on an object whose SACL audits that right. Where 4656 shows the handle request, 4663 shows the operation: reading data, writing, deleting, changing permissions. There is no Failure version; refused access only appears as a Failure 4656.

Read AccessList or AccessMask to know what happened. For files, 0x1 is ReadData, 0x2 WriteData, 0x10000 DELETE and 0x40000 WRITE_DAC. For registry keys the same bits carry different names (0x1 is Query key value, 0x2 Set key value, 0x8 Enumerate sub-keys). DELETE is also logged for renames and moves, so use 4660 to confirm a real deletion.

4663 is only as good as the SACLs deployed. It is the standard way to audit sensitive shares and folders, but auditing reads on busy data produces huge volume; audit writes and deletes broadly and reads only where they matter.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit File System, Audit Registry, Audit Kernel Object or Audit Removable Storage (Success), plus a SACL on the object that audits the right being used.

Enabling the subcategory alone logs nothing for ordinary files; SACLs must be set by GPO (File System / Registry security or Global Object Access Auditing) or on each object.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that used the access.
SubjectLogonIdLogon session; pivot to 4624 for logon type and source, and to 4688 for the process tree.
ObjectServerSubsystem, normally Security.
ObjectTypeFile for files and folders, Key for registry keys, other types for kernel objects.
ObjectNameFull path of the object (file path or \REGISTRY\... key path).
HandleIdHandle used; links to 4656 (request), 4660 (delete) and 4658 (close) from the same process.
AccessListRights used, as message codes (see values).
ValueMeaning
%%4416ReadData / ListDirectory (registry — Query key value).
%%4417WriteData / AddFile (registry — Set key value).
%%4418AppendData / AddSubdirectory / CreatePipeInstance.
%%4419ReadEA (registry — Enumerate sub-keys).
%%4420WriteEA.
%%4421Execute / Traverse.
%%4422DeleteChild.
%%4423ReadAttributes.
%%4424WriteAttributes.
%%1537DELETE — also logged for renames and moves.
%%1538READ_CONTROL — read the security descriptor (not the SACL).
%%1539WRITE_DAC — change permissions.
%%1540WRITE_OWNER — take ownership.
%%1541SYNCHRONIZE.
%%1542ACCESS_SYS_SEC — read or change the SACL.
AccessMaskHexadecimal mask of the rights used; a combination of the bits below.
ValueMeaning
0x1ReadData / ListDirectory.
0x2WriteData / AddFile.
0x4AppendData / AddSubdirectory.
0x8ReadEA.
0x10WriteEA.
0x20Execute / Traverse.
0x40DeleteChild.
0x80ReadAttributes.
0x100WriteAttributes.
0x10000DELETE.
0x20000READ_CONTROL.
0x40000WRITE_DAC.
0x80000WRITE_OWNER.
0x100000SYNCHRONIZE.
0x1000000ACCESS_SYS_SEC.
ProcessNameProcess that used the access. For remote SMB access on a file server this is System.
ProcessIdHexadecimal PID of that process.
ResourceAttributesCentral access policy resource attributes of the object, when Dynamic Access Control is used.

Common benign sources

  • Users opening and saving documents in audited folders.
  • Backup, antivirus and search indexer processes reading large numbers of audited files.
  • Applications updating their own configuration files or registry keys.

What attackers do that produces it

  • Bulk reads of sensitive shares or folders by one account before exfiltration.
  • Mass WriteData and DELETE activity from a single process, typical of ransomware encrypting and renaming files.
  • Access to credential stores covered by a SACL, such as copies of NTDS.dit or registry hive backups, by unexpected processes.
  • WRITE_DAC or WRITE_OWNER on sensitive files to grant the attacker access.

Investigation tips

  • Decode AccessMask first; reads, writes, deletes and permission changes are very different stories.
  • Aggregate by SubjectUserName, ProcessName and folder to spot bulk access in a short window.
  • For file servers, pair with 5145 to get the client IP and share name of SMB access.
  • Confirm deletions with 4660 (same HandleId and ProcessId) and permission changes with 4670.

MITRE ATT&CK techniques

TechniqueTactics
T1005 Data from Local SystemCollection
T1039 Data from Network Shared DriveCollection
T1070.004 Indicator Removal: File DeletionStealth
T1485 Data DestructionImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

14 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Critical · 1
  • High · 3
  • Medium · 9
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4663: An attempt was made to access an object

Sources and further reading