Skip to content
Security

Event ID 4661: SAM or AD handle requested

A handle to an object was requestedSecurity event 4661 logs a handle request on a SAM or Active Directory object. On DCs it exposes SAMR enumeration of users and groups such as Domain Admins.
4661
Event ID
4661
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Active Directory
Default logging
Needs configuration

What event 4661 means

Event 4661 is the SAM and directory counterpart of 4656. It is written when a process opens a handle to a Security Account Manager object — a domain, user, group or alias — or to an Active Directory object. ObjectServer tells the two apart: Security Account Manager or DS.

Its main use in hunting is SAMR reconnaissance. Tools such as net user /domain, net group "Domain Admins" /domain and AD collectors that enumerate sessions and group membership over SAMR open handles on SAM user and group objects on the domain controller. The records show who asked, for which object type and from which logon session.

Volume on domain controllers is high, since legitimate Windows components query SAM constantly. Treat 4661 as a source for baselining and targeted hunts rather than a single-event alert.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit SAM, or DS Access > Audit Directory Service Access (Success and/or Failure), with an auditing ACE on the object.

Microsoft documents that the event also depends on Audit Handle Manipulation (Success) being enabled. Verify the effective policy with auditpol before relying on it.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that requested the handle.
SubjectLogonIdLogon session of that account; on a DC, pivot to the network logon (4624 type 3) for the source IP.
ObjectServerSecurity Account Manager for SAM objects, DS for Active Directory objects.
ObjectTypeKind of object requested.
ValueMeaning
SAM_DOMAINA domain; the typical value for Active Directory events.
SAM_USERA user account.
SAM_GROUPA group that is not a local group (domain global or universal group).
SAM_ALIASA local (alias) group, including domain-local and builtin groups.
SAM_SERVERThe SAM server object.
ObjectNameName of the object; depending on the type, a distinguished name or a SID. SIDs ending in -512 (Domain Admins) or -500 (built-in Administrator) are common enumeration targets.
HandleIdHandle value for correlation with later events on the same object.
AccessListRequested rights as message codes.
AccessMaskHexadecimal mask of the requested rights.
PropertiesFor DS objects, the access type and GUIDs of the classes or property sets involved.
ProcessNameProcess that requested the handle; on DCs usually lsass.exe acting for a remote client.

Common benign sources

  • Windows clients and servers resolving group memberships and account names during logon and policy processing.
  • Management tools (ADUC, identity management and audit products) reading accounts and groups.
  • Domain controllers and member servers querying their own SAM during normal operation.

What attackers do that produces it

  • Domain reconnaissance over SAMR: a user workstation account session enumerating many SAM_USER and SAM_GROUP objects, or specifically Domain Admins, in a short time.
  • Automated AD collection tools producing bursts of handle requests from one logon session.

Investigation tips

  • Baseline which accounts normally generate 4661 on DCs, then look for regular users with unusually high counts or queries for privileged groups.
  • Pivot SubjectLogonId to the DC's 4624 to find the source computer and IP of the enumeration.
  • Correlate with 4799 and 4798 on member servers, which record local group and user enumeration.

MITRE ATT&CK techniques

TechniqueTactics
T1087.002 Account Discovery: Domain AccountDiscovery
T1069.002 Permission Groups Discovery: Domain GroupsDiscovery

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading