Skip to content
Security

Event ID 4662: AD object operation

An operation was performed on an objectSecurity event 4662 logs an operation on an Active Directory object. With the replication rights GUIDs in Properties, it is the classic DCSync detection.
4662
Event ID
4662
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Active Directory
Default logging
Needs configuration

What event 4662 means

Event 4662 is written on a domain controller when an operation is performed on an Active Directory object whose SACL audits it: reading or writing properties, deleting, changing permissions, or exercising an extended right (control access). The raw XML identifies objects and classes by GUID: ObjectType and ObjectName appear as %{GUID} and Properties lists the access type followed by the GUIDs of the classes, property sets or extended rights involved.

Its best-known use is DCSync detection. Replicating secrets from a DC through the directory replication service requires the DS-Replication-Get-Changes (1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) extended rights on the domain object. A 4662 with AccessMask 0x100 (Control Access) and those GUIDs in Properties, where the subject is not a domain controller computer account, is a strong sign of credential theft by Mimikatz lsadump::dcsync or similar tools.

The event is also useful for access to sensitive attributes and objects, but it needs careful SACL design: auditing Read Property widely on a busy directory generates enormous volume.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > DS Access > Audit Directory Service Access (Success), applied to domain controllers, plus an auditing ACE on the object (for DCSync, on the domain root object) covering the operation.

Check the effective policy on DCs with auditpol /get /category:"DS Access" and the domain root SACL before relying on this event. Only logged on domain controllers.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that performed the operation. For replication, legitimate values are domain controller computer accounts (ending in $) and known sync accounts.
SubjectUserSidSID of that account; stable across renames.
SubjectLogonIdLogon session; pivot to 4624 on the same DC for the source IP.
ObjectServerAlways DS for this event.
ObjectTypeClass of the object, as a schema GUID in the XML, e.g. %{19195a5b-6da0-11d0-afd3-00c04fd930c9} for domainDNS (the domain root).
ObjectNameObject that was accessed, as %{objectGUID} in the XML or a distinguished name when rendered.
OperationTypeTypically Object Access.
AccessListRights used, as message codes; the rendered text names the right (e.g. Control Access).
AccessMaskHexadecimal mask of the rights used.
ValueMeaning
0x10Read Property.
0x20Write Property.
0x100Control Access — an extended right was exercised (DCSync, password reset, etc.).
0x10000DELETE (also logged when an object is moved).
0x40000WRITE_DAC — the object's permissions were modified.
0x80000WRITE_OWNER — ownership was taken.
PropertiesAccess type followed by the GUIDs involved. Look here for {1131f6aa-9c07-11d1-f79f-00c04fc2dcd2} (DS-Replication-Get-Changes), {1131f6ad-9c07-11d1-f79f-00c04fc2dcd2} (DS-Replication-Get-Changes-All) and {89e95b76-444d-4c62-991a-0facbeda640c} (DS-Replication-Get-Changes-In-Filtered-Set).
AdditionalInfoExtra operation details, often -.

Common benign sources

  • Domain controllers replicating with each other; the subject is a DC computer account such as DC02$.
  • Directory synchronization services (for example the Microsoft Entra Connect sync account) that hold replication rights by design.
  • Administrators and management tools touching audited objects during routine AD administration.

What attackers do that produces it

  • DCSync: a user or non-DC computer account exercising the replication extended rights on the domain object to pull password hashes, including krbtgt.
  • Changing the permissions (WRITE_DAC) of the domain object or AdminSDHolder to grant an account replication rights for later DCSync.
  • Reading or modifying sensitive objects and attributes covered by a SACL, such as privileged groups.

Investigation tips

  • For DCSync, filter on AccessMask 0x100 and the two replication GUIDs in Properties, then drop subjects that are DC computer accounts or documented sync accounts.
  • Pivot SubjectLogonId to the 4624 on the same DC to get the source IP, and confirm whether that IP belongs to a domain controller.
  • Check 5136 for recent nTSecurityDescriptor changes on the domain root that could have granted replication rights.
  • Expect follow-on use of stolen hashes, such as 4769 or 4624 activity with the harvested accounts.

MITRE ATT&CK techniques

TechniqueTactics
T1003.006 OS Credential Dumping: DCSyncCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

7 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Critical · 2
  • High · 3
  • Medium · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading