Skip to content
Security

Event ID 4731: Local group created

A security-enabled local group was createdSecurity event 4731 is logged when a security-enabled local group is created — a local SAM group on a host, or a domain local group on a domain controller.
4731
Event ID
4731
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4731 means

Event 4731 is written when a new security-enabled local group is created. On workstations and member servers this is a group in the local SAM; on domain controllers it is a domain local security group in Active Directory. Global groups are reported by 4727 and universal groups by 4754.

TargetUserName, TargetDomainName and TargetSid identify the new group, SamAccountName holds its pre-Windows 2000 name, and Subject* identifies the creator. A new group by itself grants nothing; what matters is where the group is then used — its members (4732) and the permissions or rights it receives.

Local group creation on endpoints is uncommon outside software installation, so it is worth a quick review.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Key fields

FieldWhat it tells you
TargetUserNameName of the new group.
TargetDomainNameDomain of the group, or the computer name for a local SAM group.
TargetSidSID of the new group.
SamAccountNamePre-Windows 2000 name of the group.
SidHistoryPrevious SIDs of a migrated group; - for a newly created group.
SubjectUserNameAccount that created the group.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Applications and roles creating their own local groups during installation (SQL Server, Hyper-V, IIS and similar).
  • Administrators creating domain local groups for resource permissions (AGDLP model).

What attackers do that produces it

  • Creating a group with an innocuous name to hold backdoor accounts and later grant it rights on hosts or objects.

Investigation tips

  • Check who created the group and whether it matches a software installation or change request.
  • Follow the TargetSid in later 4732 events and in permission changes to see what the group was used for.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading