Skip to content
Security

Event ID 4755: Universal group changed

A security-enabled universal group was changedSecurity event 4755 is logged on a domain controller when a security-enabled universal group is changed; most instances accompany membership changes.
4755
Event ID
4755
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4755 means

Event 4755 is written on the domain controller that processed the change when a security-enabled universal group is modified. It is the universal-group equivalent of 4735 (local and domain local groups) and 4737 (global groups), with the same fields.

Only SamAccountName and SidHistory are shown when they change; other modifications leave every attribute at -. An empty 4755 typically accompanies each membership change (4756, 4757), and a rename also produces 4781.

Use it as a marker and read it together with the membership events in the same second, or with 5136 when directory service change auditing is enabled.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers.

Key fields

FieldWhat it tells you
TargetUserNameName of the changed group (the new name after a rename).
TargetDomainNameDomain of the group.
TargetSidSID of the group.
SamAccountNameNew pre-Windows 2000 name if it changed, otherwise -.
SidHistoryNew SID history if it changed, otherwise -.
SubjectUserNameAccount that changed the group.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Empty 4755 events logged with ordinary membership changes.
  • Group renames or conversions during directory reorganizations.

What attackers do that produces it

  • Renaming or adding SID history to a privileged universal group to disguise it.

Investigation tips

  • Correlate with 4756 and 4757 in the same second to identify the membership change.
  • When SamAccountName is set, find the matching 4781 for the old name.
  • Use 5136 to see which attribute changed when the event shows only dashes.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading