Skip to content
Security

Event ID 4743: Computer account deleted

A computer account was deletedSecurity event 4743 is logged on a domain controller when a computer account is deleted from Active Directory, with who deleted it and the account's SID.
4743
Event ID
4743
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Needs configuration

What event 4743 means

Event 4743 is written on the domain controller that processed the request when a computer object is deleted. Subject* identifies who deleted it and Target* the deleted computer account (name ending in $).

Deletion of computer accounts is part of normal lifecycle management — stale-object cleanup and hardware decommissioning. It becomes important when the deleted object is a domain controller, a critical server or an administrative workstation: the machine loses its trust with the domain and can no longer authenticate users.

After attacks that rely on a machine account created through the machine account quota, intruders sometimes delete that account to remove evidence; a 4743 shortly after the matching 4741 is a pattern worth hunting for.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Computer Account Management (Success).

Only generated on domain controllers. This subcategory is not part of the Windows default audit policy table published by Microsoft, although many domain controller baselines (Microsoft security baselines, CIS) enable it; confirm with auditpol /get /subcategory:"Computer Account Management".

Key fields

FieldWhat it tells you
SubjectUserNameAccount that deleted the computer object.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
TargetUserNameName of the deleted computer account, ending in $.
TargetDomainNameDomain of the deleted account.
TargetSidSID of the deleted computer account; search older events for it.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Cleanup scripts removing stale computer objects.
  • Decommissioning or reimaging of workstations and servers.

What attackers do that produces it

  • Deleting a computer account created for an attack (RBCD, noPac) to cover tracks.
  • Deleting domain controller or server accounts to disrupt authentication.

Investigation tips

  • Look for the account's creation (4741) and changes (4742, 4781) using TargetSid and check how long it existed.
  • Treat deletion of DC, tier-0 server or admin workstation accounts as high priority.

MITRE ATT&CK techniques

TechniqueTactics
T1070.009 Indicator Removal: Clear PersistenceStealth
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading