Event ID 4907: Object SACL changed
- Event ID
- 4907
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 4907 means
Event 4907 is written when the SACL of an object such as a file, folder or registry key changes — the auditing entries that decide whether access to it produces 4656 and 4663. OldSd and NewSd contain the security descriptors in SDDL, with the audit ACEs in the S: section.
Removing an audit ACE from a sensitive file or key silently stops its access records without touching the system audit policy (4719). That makes 4907 the place to catch targeted blinding of object auditing. It is not generated for Active Directory objects; directory SACL changes appear in 5136 as nTSecurityDescriptor modifications.
Expect substantial noise: Windows servicing (TiWorker.exe, TrustedInstaller.exe) rewrites security descriptors on system files during updates.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Audit Policy Change (Success). Enabled for Success in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that changed the SACL; often SYSTEM for Windows servicing. |
| SubjectLogonId | Logon session of the subject. |
| ObjectServer | Subsystem, normally Security. |
| ObjectType | File or Key, for example. |
| ObjectName | Path of the object whose SACL changed. |
| HandleId | Handle used for the change. |
| OldSd | Previous security descriptor in SDDL; the S: part holds the audit ACEs. |
| NewSd | New security descriptor; compare the S: part with OldSd. |
| ProcessName | Process that changed the SACL. |
| ProcessId | Hexadecimal PID of that process. |
Common benign sources
- Windows Update and component servicing (
TiWorker.exe,TrustedInstaller.exe) touching system files. - Group Policy applying File System or Registry auditing settings, or Global Object Access Auditing.
- Administrators configuring audit entries on folders with Explorer or PowerShell.
What attackers do that produces it
- Removing audit ACEs from sensitive files, folders or registry keys before accessing them.
- Changing SACLs so that only failures, or nothing, is audited on a monitored share.
Investigation tips
- Exclude Windows servicing processes, then diff the
S:section ofOldSdandNewSd. - Flag changes where audit ACEs disappear from objects covered by detection use cases.
- Pivot
SubjectLogonIdto 4688 to find the tool that made the change.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685.001 Disable or Modify Tools: Disable or Modify Windows Event Log | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.