﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>WinSecWiki » Windows Security Settings » Local Policies » Audit Policy » Audit object access</title><generator>InstantKB.NET 2.0.3</generator><description>WinSecWiki</description><link>http://www.ultimatewindowssecurity.com/wiki/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Thu, 20 Jun 2013 04:10:25 GMT</lastBuildDate><ttl>20</ttl><item><title>Removable Storage Devices</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50634.aspx</link><description>In Windows Server 2012 and Windows 8, when a user attempts to access a removable storage device Success audit Event 4663 or Failure audits Event 4656 is generated each time. Failure events will not be generated unless Audit Handle Manipulation is also configured.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=17"&gt;&lt;font color="#1f5080" size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;/font&gt;&lt;span&gt;&lt;font color="#000000" size="2"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;&lt;font color="#1f5080"&gt;4656&lt;/font&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;&lt;font color="#1f5080"&gt;A handle to an object was requested&lt;/font&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;&lt;font color="#1f5080"&gt;4663&lt;/font&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;&lt;font color="#1f5080"&gt;An attempt was made to access an object&lt;/font&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="lblSpacer"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a name="comments"&gt;&lt;/a&gt;&lt;div id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_ctlAddArticleComments_ctlUpdatePanel"&gt;&lt;/div&gt;</description><pubDate>Mon, 17 Jun 2013 16:51:59 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Handle Manipulation</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50596.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category logs one and only one event. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy&lt;/font&gt;&lt;/font&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;. &lt;br /&gt;&lt;br /&gt;In Server 2012, to log removable storage device failure events, handle manipulation must also be enabled.&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;br /&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=23"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4690" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4690"&gt;4690&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4690" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4690"&gt;An attempt was made to duplicate a handle to an object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Mon, 17 Jun 2013 15:27:01 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Other Object Access Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50600.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This is a hodgepodge of miscellaneous Object Access events. The most valuable event in this category are the ones allowing you to monitor changes to Scheduled Tasks and file deletion. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=27"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;4656&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;A handle to an object was requested&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;4658&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;The handle to an object was closed&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4659" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4659"&gt;4659&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4659" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4659"&gt;A handle to an object was requested with intent to delete&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;4660&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;An object was deleted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;4663&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;An attempt was made to access an object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4664" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4664"&gt;4664&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4664" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4664"&gt;An attempt was made to create a hard link.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4691" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4691"&gt;4691&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4691" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4691"&gt;Indirect access to an object was requested&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4698" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4698"&gt;4698&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4698" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4698"&gt;A scheduled task was created&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4699" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4699"&gt;4699&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4699" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4699"&gt;A scheduled task was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4700" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4700"&gt;4700&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4700" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4700"&gt;A scheduled task was enabled.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4701" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4701"&gt;4701&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4701" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4701"&gt;A scheduled task was disabled&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4702" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4702"&gt;4702&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4702" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4702"&gt;A scheduled task was updated.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:09:08 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Filtering Platform Connection</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50599.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;As the name would indicate, this category logs events associated with network connections permitted or blocked by Windows Firewall and the lower level Windows Filtering Platform. What's it doing in the higher level Object Access category? Who knows. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=26"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5031" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5031"&gt;5031&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5031" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5031"&gt;The Windows Firewall Service blocked an application from accepting incoming connections on the network.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5154" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5154"&gt;5154&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5154" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5154"&gt;The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5155" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5155"&gt;5155&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5155" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5155"&gt;The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5156" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5156"&gt;5156&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5156" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5156"&gt;The Windows Filtering Platform has allowed a connection&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5157" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5157"&gt;5157&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5157" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5157"&gt;The Windows Filtering Platform has blocked a connection&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5158" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5158"&gt;5158&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5158" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5158"&gt;The Windows Filtering Platform has permitted a bind to a local port.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5159" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5159"&gt;5159&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5159" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5159"&gt;The Windows Filtering Platform has blocked a bind to a local port.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:07:33 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Filtering Platform Packet Drop</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50598.aspx</link><description>&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;span&gt;&lt;font color="#000000" size="2"&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;As the name would indicate, the category logs events associated with packets blocked by Windows Firewall and the lower level Windows Filtering Platform. What's it doing in the higher level Object Access category? Who knows. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=25"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5152" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5152"&gt;5152&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5152" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5152"&gt;The Windows Filtering Platform blocked a packet.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5153" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5153"&gt;5153&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5153" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5153"&gt;A more restrictive Windows Filtering Platform filter has blocked a packet.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;</description><pubDate>Tue, 28 Aug 2012 17:04:56 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>File Share</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50597.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category logs one and only one event. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy&lt;/font&gt;&lt;/font&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=24"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5140" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5140"&gt;5140&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5140" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5140"&gt;A network share object was accessed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:03:00 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Application Generated</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50595.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category apparently logs provides a way for applications to report audit events to the security log and is no doubt related to Authorization Manager. I've not researched this category and welcome any help from the community in documenting it. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;This category is also used by the &lt;a href="/sharepoint/logbindersp/default.aspx"&gt;LOGbinder&lt;/a&gt; family of agents for reporting application audit events from SharePoint, SQL Server and more.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=22"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4665" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4665"&gt;4665&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4665" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4665"&gt;An attempt was made to create an application client context.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4666" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4666"&gt;4666&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4666" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4666"&gt;An application attempted an operation&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4667" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4667"&gt;4667&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4667" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4667"&gt;An application client context was deleted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4668" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4668"&gt;4668&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4668" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4668"&gt;An application was initialized.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?source=sp"&gt;10-59&lt;/a&gt;    &lt;/td&gt;&lt;td&gt;SharePoint Audit Events Generated by &lt;a href="/sharepoint/logbindersp/default.aspx"&gt;LOGbinder SP&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:57:30 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Certification Services</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50594.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;Certification Services is the built-in Certification Authority and related PKI functionality in Windows Server and this category provides exhaustive auditing of related activity. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=21"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4868" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4868"&gt;4868&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4868" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4868"&gt;The certificate manager denied a pending certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4869" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4869"&gt;4869&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4869" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4869"&gt;Certificate Services received a resubmitted certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4870" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4870"&gt;4870&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4870" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4870"&gt;Certificate Services revoked a certificate.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4871" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4871"&gt;4871&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4871" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4871"&gt;Certificate Services received a request to publish the certificate revocation list (CRL).&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4872" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4872"&gt;4872&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4872" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4872"&gt;Certificate Services published the certificate revocation list (CRL).&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4873" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4873"&gt;4873&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4873" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4873"&gt;A certificate request extension changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4875" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4875"&gt;4875&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4875" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4875"&gt;Certificate Services received a request to shut down.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4876" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4876"&gt;4876&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4876" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4876"&gt;Certificate Services backup started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4877" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4877"&gt;4877&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4877" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4877"&gt;Certificate Services backup completed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4878" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4878"&gt;4878&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4878" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4878"&gt;Certificate Services restore started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4879" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4879"&gt;4879&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4879" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4879"&gt;Certificate Services restore completed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4880" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4880"&gt;4880&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4880" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4880"&gt;Certificate Services started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4881" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4881"&gt;4881&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4881" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4881"&gt;Certificate Services stopped.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4882" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4882"&gt;4882&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4882" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4882"&gt;The security permissions for Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4883" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4883"&gt;4883&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4883" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4883"&gt;Certificate Services retrieved an archived key.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4884" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4884"&gt;4884&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4884" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4884"&gt;Certificate Services imported a certificate into its database.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4885" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4885"&gt;4885&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4885" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4885"&gt;The audit filter for Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4886" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4886"&gt;4886&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4886" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4886"&gt;Certificate Services received a certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4887" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4887"&gt;4887&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4887" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4887"&gt;Certificate Services approved a certificate request and issued a certificate.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4888" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4888"&gt;4888&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4888" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4888"&gt;Certificate Services denied a certificate request.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4889" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4889"&gt;4889&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4889" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4889"&gt;Certificate Services set the status of a certificate request to pending.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4890" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4890"&gt;4890&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4890" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4890"&gt;The certificate manager settings for Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4891" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4891"&gt;4891&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4891" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4891"&gt;A configuration entry changed in Certificate Services.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4892" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4892"&gt;4892&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4892" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4892"&gt;A property of Certificate Services changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4893" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4893"&gt;4893&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4893" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4893"&gt;Certificate Services archived a key.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4894" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4894"&gt;4894&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4894" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4894"&gt;Certificate Services imported and archived a key.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4895" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4895"&gt;4895&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4895" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4895"&gt;Certificate Services published the CA certificate to Active Directory Domain Services.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4896" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4896"&gt;4896&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4896" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4896"&gt;One or more rows have been deleted from the certificate database.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4897" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4897"&gt;4897&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4897" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4897"&gt;Role separation enabled&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4898" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4898"&gt;4898&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4898" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4898"&gt;Certificate Services loaded a template.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4899" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4899"&gt;4899&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4899" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4899"&gt;A Certificate Services template was updated.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4900" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4900"&gt;4900&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4900" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4900"&gt;Certificate Services template security was updated.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:54:07 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>SAM</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50593.aspx</link><description>&lt;font color="#000000" size="1"&gt;This category allows you to track access to objects in the SAM (Security Account Manager) where local users and groups are stored on non-domain controller systems. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=20"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;/font&gt;&lt;span&gt;&lt;font color="#000000"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;4658&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;The handle to an object was closed&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;4660&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;An object was deleted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4661" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4661"&gt;4661&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4661" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4661"&gt;A handle to an object was requested&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;4663&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;An attempt was made to access an object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:51:33 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Kernal Object</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50592.aspx</link><description>This sub-category is probably only of interest to developers. An example of a kernel object is a security token. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;table id="ctl00_ctl00_ctl00_ctl00_Content_Content_Content_Content_GridView1" style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; BORDER-COLLAPSE: collapse; FONT-SIZE: smaller; BORDER-TOP: 0px; BORDER-RIGHT: 0px" border="0" rules="all" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align="right" style="BORDER-BOTTOM-STYLE: none; BORDER-RIGHT-STYLE: none; WIDTH: 100px; BORDER-TOP-STYLE: none; BORDER-LEFT-STYLE: none"&gt;&lt;/td&gt;&lt;td align="center" style="BORDER-BOTTOM-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-TOP-STYLE: none; BORDER-LEFT-STYLE: none"&gt;&lt;a style="MARGIN-LEFT: 5px; MARGIN-RIGHT: 5px" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;&lt;font color="#006699"&gt;4656&lt;/font&gt;&lt;/a&gt; &lt;/td&gt;&lt;td style="BORDER-BOTTOM-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-TOP-STYLE: none; BORDER-LEFT-STYLE: none"&gt;&lt;a href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;&lt;font color="#006699"&gt;A handle to an object was requested&lt;/font&gt;&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align="right" style="BORDER-BOTTOM-STYLE: none; BORDER-RIGHT-STYLE: none; WIDTH: 100px; BORDER-TOP-STYLE: none; BORDER-LEFT-STYLE: none"&gt;&lt;/td&gt;&lt;td align="center" style="BORDER-BOTTOM-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-TOP-STYLE: none; BORDER-LEFT-STYLE: none"&gt;&lt;a style="MARGIN-LEFT: 5px; MARGIN-RIGHT: 5px" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;&lt;font color="#006699"&gt;4658&lt;/font&gt;&lt;/a&gt; &lt;/td&gt;&lt;td style="BORDER-BOTTOM-STYLE: none; BORDER-RIGHT-STYLE: none; BORDER-TOP-STYLE: none; BORDER-LEFT-STYLE: none"&gt;&lt;a href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;&lt;font color="#006699"&gt;The handle to an object was closed&lt;/font&gt;&lt;/a&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:47:21 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Registry</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50591.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category allows you to track access to registry keys and values. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=18"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;4656&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;A handle to an object was requested&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4657" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4657"&gt;4657&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4657" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4657"&gt;A registry value was modified&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;4658&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;The handle to an object was closed&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;4660&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;An object was deleted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;4663&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;An attempt was made to access an object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:22:24 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>File System</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50590.aspx</link><description>&lt;font color="#000000" size="1"&gt;This category allows you to track access to files and folders. To enable or disable this category you must use the auditpol command.&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=17"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;/font&gt;&lt;span&gt;&lt;font color="#000000" size="2"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;4656&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4656" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4656"&gt;A handle to an object was requested&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;4658&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4658" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4658"&gt;The handle to an object was closed&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;4660&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4660" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4660"&gt;An object was deleted&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;4663&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4663" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4663"&gt;An attempt was made to access an object&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4685" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4685"&gt;4685&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4685" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4685"&gt;The state of a transaction has changed&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4985" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4985"&gt;4985&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4985" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4985"&gt;The state of a transaction has changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:19:11 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Detailed File Share</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50627.aspx</link><description>&lt;font size="1"&gt;This category does not exist prior to R2 of Windows Server 2008 or Windows 7.&lt;br /&gt;&lt;br /&gt;This category logs one and only one event. Windows 7 and Server 2008 R2 and later can use Group Policy to enable it&lt;/font&gt;&lt;font color="#000000"&gt;&lt;font size="1"&gt;. &lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9&amp;amp;subcatid=24"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5145" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5145"&gt;5145&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5145" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5145"&gt;A network share object was checked to see whether client can be granted desired access.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 16:12:48 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>OVERVIEW: Audit Object Access</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50027.aspx</link><description>&lt;span style="FONT-SIZE: 12px; COLOR: rgb(51,51,51); FONT-FAMILY: Verdana"&gt;&lt;font size="1"&gt; &lt;span style="COLOR: rgb(0,0,0)"&gt;The Audit object access policy handles auditing access to all objects outside AD. The first use you might think of for the policy is file and folder auditing, but you can use it to audit access to any type of Windows object including registry keys, printers, and services. Furthermore, auditing access to an object such as a crucial file requires you to enable more than just this category; you must also enable auditing for the specific objects you want to track. To configure an object’s audit policy, open the object's Properties, select the Security tab, click Advanced, and then select the Auditing tab. &lt;/span&gt;&lt;strong&gt;&lt;span style="COLOR: rgb(0,0,0)"&gt;Be warned: This policy can really bog down your server if you enable it on too many objects. &lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;font color="#000000"&gt;The following is an excerpt from my book , &lt;/font&gt;&lt;/font&gt;&lt;span style="COLOR: rgb(0,0,0)"&gt;&lt;a href="/securitylog/resourcekits/Default.aspx"&gt;&lt;font color="#1f5080" size="1"&gt;The Windows Server Security Log Revealed &lt;/font&gt;&lt;/a&gt;&lt;font color="#000000" size="1"&gt;: &lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;font class="Quote" color="#000000"&gt;You can use the Object Access Security log category to audit any and all attempts to access files and other Windows objects. The only auditable objects not covered by this category are AD objects, which you can track by using the Directory Service category. In addition to tracking files, you can track success and failure access attempts on folders, services, registry keys, and printer objects. The way in which you define Object Access audit policy and the format of information recorded in the Security log for this category are closely related to the structure of the ACLs that all objects use to define who can access the object and how. &lt;br /&gt;&lt;br /&gt;When you enable the Audit object access events policy for a given computer, Windows doesn’t immediately begin auditing all access events for all objects because the system would immediately grind to a halt. Activating object access auditing is a two-step procedure. First, enable the Audit object access events policy on the system that contains the objects you want to monitor. Second, select specific objects and define the types of access you want to monitor. you make these selections in the object’s audit settings, which you’ll find on the object's Advanced Security Settings dialog box. For instance, Figure 7-1 displays the audit settings for a folder named Accounting Data. &lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table class="imageauto" cellspacing="0" cellpadding="0" align="center"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;img class="image" style="WIDTH: 468px; HEIGHT: 367px" alt="Image" src="/images/auditsacloffolder7-1.jpg" /&gt; &lt;p class="imagedescription"&gt;Figure 7‑1 Object audit policy &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;font size="1"&gt;For a list of Event IDs generated by this category, see the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=9"&gt;Security Log Encyclopedia&lt;/a&gt;.&lt;/font&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;&lt;br /&gt;&lt;br /&gt;Bottom Line &lt;/h2&gt;&lt;span style="FONT-SIZE: 11px; COLOR: rgb(0,0,0); FONT-FAMILY: Verdana"&gt;&lt;font color="#000000"&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="1"&gt;Windows XP, 2000 and 2003: I don’t recommend enabling this policy unless you have specific objects and permissions types planned for auditing. &lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="1"&gt;Windows Server 2008 and Vista: I don't recommend managing audit policy at this level because too much noise is generated. Use subcategories instead. &lt;/font&gt;&lt;a href="/wiki/WindowsSecuritySettings/65" target="_blank"&gt;&lt;font size="1"&gt;See Audit Category: Object Access &lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;(Windows Server 2008 and Vista).&lt;/font&gt; &lt;/li&gt;&lt;/ul&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;</description><pubDate>Thu, 02 Apr 2009 18:20:22 GMT</pubDate><dc:creator>instantasp@gmail.com</dc:creator></item></channel></rss>