Event ID 4754: Universal group created
- Event ID
- 4754
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4754 means
Event 4754 is written on the domain controller that processed the request when a new security-enabled universal group is created. Universal groups can hold members from any domain in the forest and their membership is published to the global catalog. Global groups are reported by 4727, local and domain local groups by 4731.
The fields are the same as 4727 and 4731: the new group's TargetUserName, TargetDomainName, TargetSid, SamAccountName and SidHistory, and the creator in Subject*.
As with any new group, the risk lies in what the group is given afterward: follow its SID into membership changes (4756) and permission changes.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Only generated on domain controllers.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Name of the new group. |
| TargetDomainName | Domain of the new group. |
| TargetSid | SID of the new group. |
| SamAccountName | Pre-Windows 2000 name of the group. |
| SidHistory | Previous SIDs; - for a newly created group. |
| SubjectUserName | Account that created the group. |
| SubjectDomainName | Domain of the subject. |
| SubjectLogonId | Logon session of the subject on the DC; correlate with 4624. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Administrators creating groups for cross-domain resource access.
- Products that extend Active Directory (for example Exchange) creating their universal groups during setup.
What attackers do that produces it
- Creating a group to hold backdoor accounts and later grant it rights across the forest.
Investigation tips
- Verify the creator and the business purpose of the group.
- Follow TargetSid into later 4756 events and directory changes (5136).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.