Event ID 4737: Global group changed
- Event ID
- 4737
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4737 means
Event 4737 is written on the domain controller that processed the change when a security-enabled global group is modified. It is the global-group equivalent of 4735 (local and domain local groups) and 4755 (universal groups), with the same fields.
Only SamAccountName and SidHistory are shown when they change; other modifications leave every attribute at -. An empty 4737 typically appears next to each membership change (4728, 4729). A rename also produces 4781.
On its own the event rarely tells you what changed. Read it with the membership events around it and with directory service change auditing (5136) when that subcategory is enabled.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Only generated on domain controllers.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Name of the changed group (the new name after a rename). |
| TargetDomainName | Domain of the group. |
| TargetSid | SID of the group. |
| SamAccountName | New pre-Windows 2000 name if it changed, otherwise -. |
| SidHistory | New SID history if it changed, otherwise -. |
| SubjectUserName | Account that changed the group. |
| SubjectDomainName | Domain of the subject. |
| SubjectLogonId | Logon session of the subject on the DC; correlate with 4624. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Empty 4737 events logged with ordinary membership changes.
- Group renames during reorganizations.
What attackers do that produces it
- Renaming or adding SID history to a privileged group to disguise it or extend its reach.
Investigation tips
- Correlate with 4728 and 4729 in the same second to identify the underlying membership change.
- When SamAccountName is set, find the matching 4781 for the old name.
- Use 5136 to see which attribute changed when the event shows only dashes.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.