Event Details
User Activity->Object Access->Registry Object Access->Windows 2008->EventID 4663 - An attempt was made to access an object.
EventID 4663 - An attempt was made to access an object.
 Sample:
Log Name:       Security
Source:            Microsoft-Windows-Security-Auditing
Date:              11/9/2011 5:12:18 AM
Event ID:        4663
Task Category: Registry
Level:              Information
Keywords:       Audit Success
User:               N/A
Computer:       dcc1.Logistics.corp
Description:
An attempt was made to access an object.

Subject:
	Security ID:		LOGISTICS\ALebovsky
	Account Name:	ALebovsky
	Account Domain:	LOGISTICS
	Logon ID:		0x3e7

Object:
	Object Server:	Security
	Object Type: 	Key
	Object Name:	\REGISTRY\USER\S-1-5-21-1605701383-399426181-3496453892-1604\Software\Microsoft
	Handle ID:	                     0x530

Process Information:
	Process ID:	                     0xc0c
	Process Name:	C:\Windows\regedit.exe

Access Request Information:
	Accesses:	                     Enumerate sub-keys
	Access Mask:	0x8
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category Object Access
Source Microsoft-Windows-Security-Auditing
TaskCategory Registry
EventId 4663
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime
Who Account or user name under which the activity occured. Subject: Account Name DCC1$
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "Registry Object Access" Registry Object Access
Where The name of the workstation/server where the activity was logged. Computer
Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10
Severity Specify the seriousness of the event. "Low" Low
WhoDomain Subject: Account Domain LOGISTICS
WhereDomain -
Result Successful or Failed "Successful" Successful
Object Name Object Name
Object Type Object Type
Whom -
Comments
You must be logged in to comment