Event ID 4731: Local group created
- Event ID
- 4731
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4731 means
Event 4731 is written when a new security-enabled local group is created. On workstations and member servers this is a group in the local SAM; on domain controllers it is a domain local security group in Active Directory. Global groups are reported by 4727 and universal groups by 4754.
TargetUserName, TargetDomainName and TargetSid identify the new group, SamAccountName holds its pre-Windows 2000 name, and Subject* identifies the creator. A new group by itself grants nothing; what matters is where the group is then used — its members (4732) and the permissions or rights it receives.
Local group creation on endpoints is uncommon outside software installation, so it is worth a quick review.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Name of the new group. |
| TargetDomainName | Domain of the group, or the computer name for a local SAM group. |
| TargetSid | SID of the new group. |
| SamAccountName | Pre-Windows 2000 name of the group. |
| SidHistory | Previous SIDs of a migrated group; - for a newly created group. |
| SubjectUserName | Account that created the group. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Applications and roles creating their own local groups during installation (SQL Server, Hyper-V, IIS and similar).
- Administrators creating domain local groups for resource permissions (AGDLP model).
What attackers do that produces it
- Creating a group with an innocuous name to hold backdoor accounts and later grant it rights on hosts or objects.
Investigation tips
- Check who created the group and whether it matches a software installation or change request.
- Follow the TargetSid in later 4732 events and in permission changes to see what the group was used for.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.