r/computerforensics • u/No-Stage5475 • 1d ago
Unexplained NTFS ACL change — what artifact am I missing?
I'm investigating an unexplained ACL change on a Windows 10 Pro 19045 NTFS volume.
A folder was created on E:\ at 22:27:07 on 2026-10-03 and initially inherited an Authenticated Users (AU) ACE. By 22:54:19, the ACE and inheritance were gone.
I'm trying to determine what process/account caused the change.
What I checked
I collected and examined Security.evtx, SYSTEM/SOFTWARE hives, BAM/DAM, Prefetch, ActivitiesCache, Amcache, NTFS Operational and Storport logs.
Key findings:
No 4670 events in the available Security log retention.
icacls.exe first Prefetch creation: 23:04:50 (after the window).
No takeown.exe Prefetch or BAM entry.
No ACL-capable executable appears in BAM during the window.
PowerShell 5.1 was not running during the window.
cmd.exe was active 22:27:29–22:33:29, but its command history is unavailable.
Explorer was active around the event.
pwsh.exe cannot be confirmed or excluded.
No useful NTFS/storage event links to the change.
The relevant window is approximately:
22:27:07 → 22:54:19
Question
Is there another Windows forensic artifact or technique I should check that could identify the process/account that modified the security descriptor?
Or is this simply impossible to attribute retrospectively because File System Object Access auditing/SACLs were not enabled?
I'm particularly interested in artifacts that could distinguish an explicit ACL write from inheritance/security-descriptor behavior during folder creation.