Microsoft-Windows-Security-Auditing › Event 4790

Event ID 4790 — An LDAP query group was created.

Provider
Microsoft-Windows-Security-Auditing
Channel
Security
Audit Policy
Account Management → Application Group Management
Collection Priority
Low (Microsoft-AppendixL)
Opcode
Info

Description

An LDAP query group was created.

Message #

An LDAP query group was created.

Subject:
	Security ID: %4
	Account Name: %5
	Account Domain: %6
	Logon ID: %7

Group:
	Security ID: %3
	Account Name: %1
	Account Domain: %2

Attributes:
	SAM Account Name: %9
	SID History: %10

Additional Information:
	Privileges: %8

Fields #

NameDescription
Account_Name UnicodeString[Group] Account Name.
Account_Domain UnicodeString[Group] Account Domain.
Security_ID SID[Group] Security ID.
Security_ID SID[Subject] Security ID.
Account_Name UnicodeString[Subject] Account Name.
Account_Domain UnicodeString[Subject] Account Domain.
Logon_ID HexInt64[Subject] Logon ID.
Privileges UnicodeString[Additional Information] Privileges. Privilege constants reference
SAM_Account_Name UnicodeString[Attributes] SAM Account Name.
SID_History UnicodeString[Attributes] SID History.
TargetUserName UnicodeString[Group] Account Name
TargetDomainName UnicodeString[Group] Account Domain
TargetSid SID[Group] Security ID
SubjectUserSid SID[Subject] Security ID
SubjectUserName UnicodeString[Subject] Account Name
SubjectDomainName UnicodeString[Subject] Account Domain
SubjectLogonId HexInt64[Subject] Logon ID
PrivilegeList UnicodeString[Additional Information] Privileges Privilege constants reference
SamAccountName UnicodeString[Attributes] SAM Account Name
SidHistory UnicodeString[Attributes] SID History

Detection Patterns #

References #