Event ID 4743: Computer account deleted
- Event ID
- 4743
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Needs configuration
What event 4743 means
Event 4743 is written on the domain controller that processed the request when a computer object is deleted. Subject* identifies who deleted it and Target* the deleted computer account (name ending in $).
Deletion of computer accounts is part of normal lifecycle management — stale-object cleanup and hardware decommissioning. It becomes important when the deleted object is a domain controller, a critical server or an administrative workstation: the machine loses its trust with the domain and can no longer authenticate users.
After attacks that rely on a machine account created through the machine account quota, intruders sometimes delete that account to remove evidence; a 4743 shortly after the matching 4741 is a pattern worth hunting for.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Computer Account Management (Success).
Only generated on domain controllers. This subcategory is not part of the Windows default audit policy table published by Microsoft, although many domain controller baselines (Microsoft security baselines, CIS) enable it; confirm with auditpol /get /subcategory:"Computer Account Management".
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that deleted the computer object. |
| SubjectDomainName | Domain of the subject. |
| SubjectLogonId | Logon session of the subject on the DC; correlate with 4624. |
| TargetUserName | Name of the deleted computer account, ending in $. |
| TargetDomainName | Domain of the deleted account. |
| TargetSid | SID of the deleted computer account; search older events for it. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Cleanup scripts removing stale computer objects.
- Decommissioning or reimaging of workstations and servers.
What attackers do that produces it
- Deleting a computer account created for an attack (RBCD, noPac) to cover tracks.
- Deleting domain controller or server accounts to disrupt authentication.
Investigation tips
- Look for the account's creation (4741) and changes (4742, 4781) using TargetSid and check how long it existed.
- Treat deletion of DC, tier-0 server or admin workstation accounts as high priority.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowAdd or Remove Computer from DCRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.