Event ID 4663: Object access
- Event ID
- 4663
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Object access
- Default logging
- Needs configuration
What event 4663 means
Event 4663 is written when a process uses an access right on an object whose SACL audits that right. Where 4656 shows the handle request, 4663 shows the operation: reading data, writing, deleting, changing permissions. There is no Failure version; refused access only appears as a Failure 4656.
Read AccessList or AccessMask to know what happened. For files, 0x1 is ReadData, 0x2 WriteData, 0x10000 DELETE and 0x40000 WRITE_DAC. For registry keys the same bits carry different names (0x1 is Query key value, 0x2 Set key value, 0x8 Enumerate sub-keys). DELETE is also logged for renames and moves, so use 4660 to confirm a real deletion.
4663 is only as good as the SACLs deployed. It is the standard way to audit sensitive shares and folders, but auditing reads on busy data produces huge volume; audit writes and deletes broadly and reads only where they matter.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit File System, Audit Registry, Audit Kernel Object or Audit Removable Storage (Success), plus a SACL on the object that audits the right being used.
Enabling the subcategory alone logs nothing for ordinary files; SACLs must be set by GPO (File System / Registry security or Global Object Access Auditing) or on each object.
Key fields
| Field | What it tells you | ||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that used the access. | ||||||||||||||||||||||||||||||||
| SubjectLogonId | Logon session; pivot to 4624 for logon type and source, and to 4688 for the process tree. | ||||||||||||||||||||||||||||||||
| ObjectServer | Subsystem, normally Security. | ||||||||||||||||||||||||||||||||
| ObjectType | File for files and folders, Key for registry keys, other types for kernel objects. | ||||||||||||||||||||||||||||||||
| ObjectName | Full path of the object (file path or \REGISTRY\... key path). | ||||||||||||||||||||||||||||||||
| HandleId | Handle used; links to 4656 (request), 4660 (delete) and 4658 (close) from the same process. | ||||||||||||||||||||||||||||||||
| AccessList | Rights used, as message codes (see values).
| ||||||||||||||||||||||||||||||||
| AccessMask | Hexadecimal mask of the rights used; a combination of the bits below.
| ||||||||||||||||||||||||||||||||
| ProcessName | Process that used the access. For remote SMB access on a file server this is System. | ||||||||||||||||||||||||||||||||
| ProcessId | Hexadecimal PID of that process. | ||||||||||||||||||||||||||||||||
| ResourceAttributes | Central access policy resource attributes of the object, when Dynamic Access Control is used. |
Common benign sources
- Users opening and saving documents in audited folders.
- Backup, antivirus and search indexer processes reading large numbers of audited files.
- Applications updating their own configuration files or registry keys.
What attackers do that produces it
- Bulk reads of sensitive shares or folders by one account before exfiltration.
- Mass WriteData and DELETE activity from a single process, typical of ransomware encrypting and renaming files.
- Access to credential stores covered by a SACL, such as copies of
NTDS.ditor registry hive backups, by unexpected processes. - WRITE_DAC or WRITE_OWNER on sensitive files to grant the attacker access.
Investigation tips
- Decode
AccessMaskfirst; reads, writes, deletes and permission changes are very different stories. - Aggregate by
SubjectUserName,ProcessNameand folder to spot bulk access in a short window. - For file servers, pair with 5145 to get the client IP and share name of SMB access.
- Confirm deletions with 4660 (same
HandleIdandProcessId) and permission changes with 4670.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
14 SigmaHQ detection rules (release r2026-07-01) target this event.
- Critical · 1
- High · 3
- Medium · 9
- Low · 1
- CriticalWCE wceaux.dll AccessRule by Thomas Patzke, SigmaHQ, DRL 1.1
- HighSuspicious Teams Application Related ObjectAcess EventRule by @SerkinValery, SigmaHQ, DRL 1.1
- HighSysKey Registry Keys AccessRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- HighSysmon Channel Reference DeletionRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumAzure AD Health Monitoring Agent Registry Keys AccessRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, SigmaHQ, DRL 1.1
- MediumAzure AD Health Service Agents Registry Keys AccessRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, SigmaHQ, DRL 1.1
- MediumFile Access Of Signal Desktop Sensitive DataRule by Andreas Braathen (mnemonic.io), SigmaHQ, DRL 1.1
- MediumISO Image MountedRule by Syed Hasan (@syedhasan009), SigmaHQ, DRL 1.1
- MediumLSASS Access From Non System AccountRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumPotential Secure Deletion with SDeleteRule by Thomas Patzke, SigmaHQ, DRL 1.1
- MediumPotentially Suspicious AccessMask Requested From LSASSRule by Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update), SigmaHQ, DRL 1.1
- MediumProcesses Accessing the Microphone and WebcamRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumWindows Defender Exclusion Registry Key - Write Access RequestedRule by @BarryShooshooga, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- LowService Registry Key Read Access RequestRule by Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.