Skip to content
Security

Event ID 4754: Universal group created

A security-enabled universal group was createdSecurity event 4754 is logged on a domain controller when a new security-enabled universal group is created in Active Directory.
4754
Event ID
4754
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4754 means

Event 4754 is written on the domain controller that processed the request when a new security-enabled universal group is created. Universal groups can hold members from any domain in the forest and their membership is published to the global catalog. Global groups are reported by 4727, local and domain local groups by 4731.

The fields are the same as 4727 and 4731: the new group's TargetUserName, TargetDomainName, TargetSid, SamAccountName and SidHistory, and the creator in Subject*.

As with any new group, the risk lies in what the group is given afterward: follow its SID into membership changes (4756) and permission changes.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers.

Key fields

FieldWhat it tells you
TargetUserNameName of the new group.
TargetDomainNameDomain of the new group.
TargetSidSID of the new group.
SamAccountNamePre-Windows 2000 name of the group.
SidHistoryPrevious SIDs; - for a newly created group.
SubjectUserNameAccount that created the group.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Administrators creating groups for cross-domain resource access.
  • Products that extend Active Directory (for example Exchange) creating their universal groups during setup.

What attackers do that produces it

  • Creating a group to hold backdoor accounts and later grant it rights across the forest.

Investigation tips

  • Verify the creator and the business purpose of the group.
  • Follow TargetSid into later 4756 events and directory changes (5136).

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading