Event ID 4662: AD object operation
- Event ID
- 4662
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Active Directory
- Default logging
- Needs configuration
What event 4662 means
Event 4662 is written on a domain controller when an operation is performed on an Active Directory object whose SACL audits it: reading or writing properties, deleting, changing permissions, or exercising an extended right (control access). The raw XML identifies objects and classes by GUID: ObjectType and ObjectName appear as %{GUID} and Properties lists the access type followed by the GUIDs of the classes, property sets or extended rights involved.
Its best-known use is DCSync detection. Replicating secrets from a DC through the directory replication service requires the DS-Replication-Get-Changes (1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) extended rights on the domain object. A 4662 with AccessMask 0x100 (Control Access) and those GUIDs in Properties, where the subject is not a domain controller computer account, is a strong sign of credential theft by Mimikatz lsadump::dcsync or similar tools.
The event is also useful for access to sensitive attributes and objects, but it needs careful SACL design: auditing Read Property widely on a busy directory generates enormous volume.
When it is logged
Advanced Audit Policy Configuration > DS Access > Audit Directory Service Access (Success), applied to domain controllers, plus an auditing ACE on the object (for DCSync, on the domain root object) covering the operation.
Check the effective policy on DCs with auditpol /get /category:"DS Access" and the domain root SACL before relying on this event. Only logged on domain controllers.
Key fields
| Field | What it tells you | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that performed the operation. For replication, legitimate values are domain controller computer accounts (ending in $) and known sync accounts. | ||||||||||||||
| SubjectUserSid | SID of that account; stable across renames. | ||||||||||||||
| SubjectLogonId | Logon session; pivot to 4624 on the same DC for the source IP. | ||||||||||||||
| ObjectServer | Always DS for this event. | ||||||||||||||
| ObjectType | Class of the object, as a schema GUID in the XML, e.g. %{19195a5b-6da0-11d0-afd3-00c04fd930c9} for domainDNS (the domain root). | ||||||||||||||
| ObjectName | Object that was accessed, as %{objectGUID} in the XML or a distinguished name when rendered. | ||||||||||||||
| OperationType | Typically Object Access. | ||||||||||||||
| AccessList | Rights used, as message codes; the rendered text names the right (e.g. Control Access). | ||||||||||||||
| AccessMask | Hexadecimal mask of the rights used.
| ||||||||||||||
| Properties | Access type followed by the GUIDs involved. Look here for {1131f6aa-9c07-11d1-f79f-00c04fc2dcd2} (DS-Replication-Get-Changes), {1131f6ad-9c07-11d1-f79f-00c04fc2dcd2} (DS-Replication-Get-Changes-All) and {89e95b76-444d-4c62-991a-0facbeda640c} (DS-Replication-Get-Changes-In-Filtered-Set). | ||||||||||||||
| AdditionalInfo | Extra operation details, often -. |
Common benign sources
- Domain controllers replicating with each other; the subject is a DC computer account such as
DC02$. - Directory synchronization services (for example the Microsoft Entra Connect sync account) that hold replication rights by design.
- Administrators and management tools touching audited objects during routine AD administration.
What attackers do that produces it
- DCSync: a user or non-DC computer account exercising the replication extended rights on the domain object to pull password hashes, including
krbtgt. - Changing the permissions (WRITE_DAC) of the domain object or AdminSDHolder to grant an account replication rights for later DCSync.
- Reading or modifying sensitive objects and attributes covered by a SACL, such as privileged groups.
Investigation tips
- For DCSync, filter on
AccessMask0x100and the two replication GUIDs inProperties, then drop subjects that are DC computer accounts or documented sync accounts. - Pivot
SubjectLogonIdto the 4624 on the same DC to get the source IP, and confirm whether that IP belongs to a domain controller. - Check 5136 for recent
nTSecurityDescriptorchanges on the domain root that could have granted replication rights. - Expect follow-on use of stolen hashes, such as 4769 or 4624 activity with the harvested accounts.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1003.006 OS Credential Dumping: DCSync | Credential Access |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
7 SigmaHQ detection rules (release r2026-07-01) target this event.
- Critical · 2
- High · 3
- Medium · 2
- CriticalActive Directory Replication from Non Machine AccountRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- CriticalAD Object WriteDAC AccessRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- HighDPAPI Domain Backup Key ExtractionRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- HighMimikatz DC SyncRule by Benjamin Delpy, Florian Roth (Nextron Systems), Scott Dermott, Sorina Ionescu, SigmaHQ, DRL 1.1
- HighPotential Kerberos Coercion by Spoofing SPNs via DNS ManipulationRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPotential AD User Enumeration From Non-Machine AccountRule by Maxime Thiebaut (@0xThiebaut), SigmaHQ, DRL 1.1
- MediumWMI Persistence - SecurityRule by Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.