Windows EventInformation
Windows Event ID 4964 – Microsoft-Windows-Security-Auditing: Object Access Audit Policy Changed
Event ID 4964 logs when object access audit policy settings are modified on Windows systems, indicating changes to file, folder, or registry auditing configuration.