Microsoft-Windows-Security-Auditing › Event 4817

Event ID 4817 — Auditing settings on object were changed.

Provider
Microsoft-Windows-Security-Auditing
Channel
Security
Audit Policy
Policy Change → Audit Policy Change
Collection Priority
Recommended (Yamato Security, others)
Opcode
Info

Description

Auditing settings on object were changed.

Message #

Auditing settings on object were changed.

Subject:
	Security ID: %1
	Account Name: %2
	Account Domain: %3
	Logon ID: %4

Object:
	Object Server: %5
	Object Type: %6
	Object Name: %7

Auditing Settings:
	Original Security Descriptor: %8
	New Security Descriptor: %9

Fields #

NameDescription
Security_ID SID[Subject] Security ID.
Account_Name UnicodeString[Subject] Account Name.
Account_Domain UnicodeString[Subject] Account Domain.
Logon_ID HexInt64[Subject] Logon ID.
Object_Server UnicodeString[Object] Object Server.
Object_Type UnicodeString[Object] Object Type.
Object_Name UnicodeString[Object] Object Name.
Original_Security_Descriptor UnicodeString[Auditing Settings] Original Security Descriptor.
New_Security_Descriptor UnicodeString[Auditing Settings] New Security Descriptor.
SubjectUserSid SID[Subject] Security ID
SubjectUserName UnicodeString[Subject] Account Name
SubjectDomainName UnicodeString[Subject] Account Domain
SubjectLogonId HexInt64[Subject] Logon ID
ObjectServer UnicodeString[Object] Object Server
ObjectType UnicodeString[Object] Object Type
ObjectName UnicodeString[Object] Object Name
OldSd UnicodeString[Auditing Settings] Original Security Descriptor
NewSd UnicodeString[Auditing Settings] New Security Descriptor

Community Notes #

Attackers that wish to suppress object-access logging can clear/replace the global SACL.

References #