Skip to content
Security

Event ID 4734: Local group deleted

A security-enabled local group was deletedSecurity event 4734 is logged when a security-enabled local group is deleted — a local SAM group on a host, or a domain local group on a domain controller.
4734
Event ID
4734
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4734 means

Event 4734 is written when a security-enabled local group is deleted: a group in the local SAM on a workstation or member server, or a domain local security group on a domain controller. Global and universal group deletions are reported by 4730 and 4758.

The event names the deleted group (TargetUserName, TargetSid) and the account that deleted it (Subject*). Once the group is gone, any permission that referenced it shows as an unresolved SID, so TargetSid is the key to understanding the impact.

Deleting a group removes the access of all its members at once. Unexpected deletions of groups that grant access to business applications or file shares can be sabotage, and deletion of a recently created group can be cleanup after misuse.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Key fields

FieldWhat it tells you
TargetUserNameName of the deleted group.
TargetDomainNameDomain of the group, or the computer name for a local SAM group.
TargetSidSID of the deleted group; search ACLs and older events for it.
SubjectUserNameAccount that deleted the group.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Software uninstallation removing its local groups.
  • Directory cleanup of unused domain local groups.

What attackers do that produces it

  • Removing a group created for a backdoor after use.
  • Deleting groups that grant access to critical resources to disrupt operations.

Investigation tips

  • Look for the group's creation (4731) and membership changes (4732, 4733) to reconstruct its lifetime.
  • Confirm with the resource owners whether the deletion was planned.

MITRE ATT&CK techniques

TechniqueTactics
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading