Event ID 4661: SAM or AD handle requested
- Event ID
- 4661
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Active Directory
- Default logging
- Needs configuration
What event 4661 means
Event 4661 is the SAM and directory counterpart of 4656. It is written when a process opens a handle to a Security Account Manager object — a domain, user, group or alias — or to an Active Directory object. ObjectServer tells the two apart: Security Account Manager or DS.
Its main use in hunting is SAMR reconnaissance. Tools such as net user /domain, net group "Domain Admins" /domain and AD collectors that enumerate sessions and group membership over SAMR open handles on SAM user and group objects on the domain controller. The records show who asked, for which object type and from which logon session.
Volume on domain controllers is high, since legitimate Windows components query SAM constantly. Treat 4661 as a source for baselining and targeted hunts rather than a single-event alert.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit SAM, or DS Access > Audit Directory Service Access (Success and/or Failure), with an auditing ACE on the object.
Microsoft documents that the event also depends on Audit Handle Manipulation (Success) being enabled. Verify the effective policy with auditpol before relying on it.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that requested the handle. | ||||||||||||
| SubjectLogonId | Logon session of that account; on a DC, pivot to the network logon (4624 type 3) for the source IP. | ||||||||||||
| ObjectServer | Security Account Manager for SAM objects, DS for Active Directory objects. | ||||||||||||
| ObjectType | Kind of object requested.
| ||||||||||||
| ObjectName | Name of the object; depending on the type, a distinguished name or a SID. SIDs ending in -512 (Domain Admins) or -500 (built-in Administrator) are common enumeration targets. | ||||||||||||
| HandleId | Handle value for correlation with later events on the same object. | ||||||||||||
| AccessList | Requested rights as message codes. | ||||||||||||
| AccessMask | Hexadecimal mask of the requested rights. | ||||||||||||
| Properties | For DS objects, the access type and GUIDs of the classes or property sets involved. | ||||||||||||
| ProcessName | Process that requested the handle; on DCs usually lsass.exe acting for a remote client. |
Common benign sources
- Windows clients and servers resolving group memberships and account names during logon and policy processing.
- Management tools (ADUC, identity management and audit products) reading accounts and groups.
- Domain controllers and member servers querying their own SAM during normal operation.
What attackers do that produces it
- Domain reconnaissance over SAMR: a user workstation account session enumerating many SAM_USER and SAM_GROUP objects, or specifically Domain Admins, in a short time.
- Automated AD collection tools producing bursts of handle requests from one logon session.
Investigation tips
- Baseline which accounts normally generate 4661 on DCs, then look for regular users with unusually high counts or queries for privileged groups.
- Pivot
SubjectLogonIdto the DC's 4624 to find the source computer and IP of the enumeration. - Correlate with 4799 and 4798 on member servers, which record local group and user enumeration.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighAD Privileged Users or Groups ReconnaissanceRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- HighReconnaissance ActivityRule by Florian Roth (Nextron Systems), Jack Croock (method), Jonhnathan Ribeiro (improvements), oscd.community, SigmaHQ, DRL 1.1
- MediumPassword Policy EnumeratedRule by Zach Mathis, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.