Skip to content
Security

Event ID 4735: Local group changed

A security-enabled local group was changedSecurity event 4735 is logged when a security-enabled local group is changed. It shows name or SID history changes; most instances accompany membership changes.
4735
Event ID
4735
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4735 means

Event 4735 is written when a security-enabled local group (local SAM group, or domain local group on a domain controller) is modified. Global and universal group changes are reported by 4737 and 4755.

The event only shows new values for SamAccountName and SidHistory; other attributes are shown as - even when something else changed. In practice most 4735 events carry no visible change at all: an empty 4735 is typically logged right before each 4732 or 4733 membership change. Renaming a group also produces 4781, and changing a group's type produces a group-type-change event rather than 4735. Some modifications, such as the Managed By tab in Active Directory Users and Computers, generate no 4735.

Treat 4735 as a pointer: read it together with the membership events around it and, on domain controllers, with directory change auditing (5136) when you need the exact attribute that changed.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Key fields

FieldWhat it tells you
TargetUserNameName of the changed group (the new name if it was renamed).
TargetDomainNameDomain of the group, or the computer name for a local SAM group.
TargetSidSID of the changed group.
SamAccountNameNew pre-Windows 2000 name if it changed, otherwise -.
SidHistoryNew SID history value if it changed, otherwise -. A value here on a non-migrated group is suspicious.
SubjectUserNameAccount that changed the group.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Empty 4735 events logged alongside ordinary membership changes (4732, 4733).
  • Administrators renaming local or domain local groups.

What attackers do that produces it

  • Renaming a privileged group or adding SID history to hide its purpose or broaden its access.

Investigation tips

  • Look at the 4732 or 4733 events within the same second to see which membership change the 4735 belongs to.
  • If SamAccountName is set, find the matching 4781 to get the old name.
  • On domain controllers, use 5136 to see which attribute actually changed when 4735 shows no values.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading