Skip to content
Security

Event ID 4672: Special privileges assigned

Special privileges assigned to new logonEvent 4672 follows a 4624 when the new session holds sensitive privileges such as SeDebug or SeTcb — a marker of administrator logons.
4672
Event ID
4672
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Logged by default

What event 4672 means

Event 4672 is written right after a 4624 when the new logon's token contains one or more "sensitive" privileges: debugging programs, acting as part of the operating system, backup and restore, taking ownership, loading drivers and similar. In practice that means administrators, SYSTEM and some service accounts.

It shares its logon ID (SubjectLogonId) with the 4624 it belongs to, so filtering 4624 events down to those that have a matching 4672 is the quickest way to list privileged logons on a host. On domain controllers, every 4672 for a human account is worth knowing about.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Special Logon (Success). Enabled for Success in the default audit policy.

Logged for SYSTEM and machine accounts at a high rate; the interesting records are the ones for named user accounts.

Key fields

FieldWhat it tells you
SubjectUserSidSID of the account that received the privileges.
SubjectUserNameAccount that received the privileges (despite the "Subject" name, this is the account that logged on).
SubjectDomainNameDomain of that account.
SubjectLogonIdLogon session ID, equal to TargetLogonId in the matching 4624.
PrivilegeListSensitive privileges present in the token, one per line, e.g. SeDebugPrivilege, SeTcbPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeImpersonatePrivilege, SeSecurityPrivilege.

Common benign sources

  • Administrators logging on to servers they manage.
  • SYSTEM, LOCAL SERVICE, NETWORK SERVICE and machine accounts at boot and for services.
  • Backup software service accounts (SeBackupPrivilege, SeRestorePrivilege).

What attackers do that produces it

  • Use of a stolen admin account — a 4624 + 4672 pair for that account from a host or IP it does not normally use.
  • Newly created or newly promoted accounts (4720, 4732, 4728) suddenly receiving special privileges.
  • Lateral movement with admin credentials produces 4624 type 3 plus 4672 on every target.

Investigation tips

  • Join 4672 to 4624 on logon ID to get LogonType and source IP for each privileged logon.
  • Baseline which human accounts get 4672 on each server; alert on new ones.
  • An account that should be a standard user getting SeDebugPrivilege means its group memberships changed — check 4732/4728/4756.

MITRE ATT&CK techniques

TechniqueTactics
T1078 Valid AccountsStealth, Persistence, Privilege Escalation, Initial Access
T1078.002 Valid Accounts: Domain AccountsStealth, Persistence, Privilege Escalation, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4672: Special privileges assigned to new logon

Sources and further reading