Skip to content
Security

Event ID 4907: Object SACL changed

Auditing settings on object were changedSecurity event 4907 logs a change to an object's auditing settings (SACL) on a file or registry key, with the old and new security descriptors.
4907
Event ID
4907
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Logged by default

What event 4907 means

Event 4907 is written when the SACL of an object such as a file, folder or registry key changes — the auditing entries that decide whether access to it produces 4656 and 4663. OldSd and NewSd contain the security descriptors in SDDL, with the audit ACEs in the S: section.

Removing an audit ACE from a sensitive file or key silently stops its access records without touching the system audit policy (4719). That makes 4907 the place to catch targeted blinding of object auditing. It is not generated for Active Directory objects; directory SACL changes appear in 5136 as nTSecurityDescriptor modifications.

Expect substantial noise: Windows servicing (TiWorker.exe, TrustedInstaller.exe) rewrites security descriptors on system files during updates.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Audit Policy Change (Success). Enabled for Success in the default Windows audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that changed the SACL; often SYSTEM for Windows servicing.
SubjectLogonIdLogon session of the subject.
ObjectServerSubsystem, normally Security.
ObjectTypeFile or Key, for example.
ObjectNamePath of the object whose SACL changed.
HandleIdHandle used for the change.
OldSdPrevious security descriptor in SDDL; the S: part holds the audit ACEs.
NewSdNew security descriptor; compare the S: part with OldSd.
ProcessNameProcess that changed the SACL.
ProcessIdHexadecimal PID of that process.

Common benign sources

  • Windows Update and component servicing (TiWorker.exe, TrustedInstaller.exe) touching system files.
  • Group Policy applying File System or Registry auditing settings, or Global Object Access Auditing.
  • Administrators configuring audit entries on folders with Explorer or PowerShell.

What attackers do that produces it

  • Removing audit ACEs from sensitive files, folders or registry keys before accessing them.
  • Changing SACLs so that only failures, or nothing, is audited on a monitored share.

Investigation tips

  • Exclude Windows servicing processes, then diff the S: section of OldSd and NewSd.
  • Flag changes where audit ACEs disappear from objects covered by detection use cases.
  • Pivot SubjectLogonId to 4688 to find the tool that made the change.

MITRE ATT&CK techniques

TechniqueTactics
T1685.001 Disable or Modify Tools: Disable or Modify Windows Event LogDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading