Event ID 4734: Local group deleted
- Event ID
- 4734
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4734 means
Event 4734 is written when a security-enabled local group is deleted: a group in the local SAM on a workstation or member server, or a domain local security group on a domain controller. Global and universal group deletions are reported by 4730 and 4758.
The event names the deleted group (TargetUserName, TargetSid) and the account that deleted it (Subject*). Once the group is gone, any permission that referenced it shows as an unresolved SID, so TargetSid is the key to understanding the impact.
Deleting a group removes the access of all its members at once. Unexpected deletions of groups that grant access to business applications or file shares can be sabotage, and deletion of a recently created group can be cleanup after misuse.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Name of the deleted group. |
| TargetDomainName | Domain of the group, or the computer name for a local SAM group. |
| TargetSid | SID of the deleted group; search ACLs and older events for it. |
| SubjectUserName | Account that deleted the group. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Software uninstallation removing its local groups.
- Directory cleanup of unused domain local groups.
What attackers do that produces it
- Removing a group created for a backdoor after use.
- Deleting groups that grant access to critical resources to disrupt operations.
Investigation tips
- Look for the group's creation (4731) and membership changes (4732, 4733) to reconstruct its lifetime.
- Confirm with the resource owners whether the deletion was planned.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1531 Account Access Removal | Impact |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.