Windows Event 4660

I

Icy_Galaxy

Hello Everyone,I'm trying actually to create a detection rule with Windows event 4660 to track any deleted object, file, directory or something like that. I know that this event is logged when an object is deleted. I checked that all the advanced audit policies are configured to Success and Failure to be able to collect the events, but when : I created a new registry key and deleted it after that, event 4660 has not been logged;I tried to deleted system registry keys but same thing;I tried to delete files and directories but also same thing.I want to know, why this event code is not generated

Continue reading...
 
Back
Top Bottom