#audit-policy
5 articles
Windows Events5
Windows Event ID 4714 – Microsoft-Windows-Security-Auditing: System Security Access Control List Was Changed
Event ID 4714 fires when the System Access Control List (SACL) is modified on a Windows system, indicating changes to audit policies or security monitoring configurations.
Windows Event ID 4692 – Microsoft-Windows-Security-Auditing: An attempt was made to backup the security audit policy
Event ID 4692 fires when Windows attempts to backup the security audit policy configuration. This security audit event tracks policy backup operations for compliance and forensic purposes.
Windows Event ID 4964 – Microsoft-Windows-Security-Auditing: Object Access Audit Policy Changed
Event ID 4964 logs when object access audit policy settings are modified on Windows systems, indicating changes to file, folder, or registry auditing configuration.
Windows Event ID 4719 – Microsoft-Windows-Security-Auditing: System Audit Policy Changed
Event ID 4719 fires when Windows audit policy settings are modified, indicating changes to security auditing configuration that affect what events get logged.
Windows Event ID 4612 – LSA: Security Audit Policy Changes
Event ID 4612 fires when Local Security Authority (LSA) audit policy settings are modified, indicating changes to Windows security auditing configuration that affect what events get logged.