Microsoft-Windows-Security-Auditing › Event 4782

Event ID 4782 — The password hash an account was accessed.

Provider
Microsoft-Windows-Security-Auditing
Channel
Security
Audit Policy
Account Management → Other Account Management Events
Collection Priority
Recommended (NSA, others)
Opcode
Info

Description

The password hash an account was accessed.

Message #

The password hash an account was accessed.

Subject:
	Security ID: %3
	Account Name: %4
	Account Domain: %5
	Logon ID: %6

Target Account:
	Account Name: %1
	Account Domain: %2

Fields #

NameDescription
Account_Name UnicodeString[Target Account] Account Name.
Account_Domain UnicodeString[Target Account] Account Domain.
Security_ID SID[Subject] Security ID.
Account_Name UnicodeString[Subject] Account Name.
Account_Domain UnicodeString[Subject] Account Domain.
Logon_ID HexInt64[Subject] Logon ID.
TargetUserName UnicodeString[Target Account] Account Name
TargetDomainName UnicodeString[Target Account] Account Domain
SubjectUserSid SID[Subject] Security ID
SubjectUserName UnicodeString[Subject] Account Name
SubjectDomainName UnicodeString[Subject] Account Domain
SubjectLogonId HexInt64[Subject] Logon ID

Community Notes #

May indicate Pass-the-Hash. Legitimate use occurs during AD password migration operations under SYSTEM or a dedicated migration account.

References #