Skip to content
Security

Event ID 4765: SID History added

SID History was added to an accountSecurity event 4765 is logged on a domain controller when SID History is added to an account — normal in migrations, a privilege escalation path otherwise.
4765
Event ID
4765
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4765 means

Event 4765 is written on a domain controller when one or more SIDs are added to an account's sIDHistory attribute. SID History exists for domain migrations: a user moved to a new domain keeps the SID of their old account so that resources still granting access to the old SID keep working. When the user logs on, every SID in the history is added to the access token.

That is exactly why it is abused. A privileged SID (for example Domain Admins or Enterprise Admins of the same or another domain) in the SID History of an ordinary account makes that account privileged without any visible group membership. The event shows the subject that made the change, the target account, the source account the SIDs came from and the SID List that was added.

Outside an active migration project this event should not occur at all. Also note that writing sIDHistory through other means — for example directly from a rogue or compromised domain controller — may not produce 4765, so review SidHistory values in 4738, 4742 and 5136 as well.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Only generated on domain controllers. Microsoft does not publish a sample of this event; the message also contains Source Account and SID List sections describing where the added SIDs came from.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that added the SID History, typically a migration service account.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameAccount that received the SID History.
TargetDomainNameDomain of the target account.
TargetSidSID of the target account.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Domain or forest migrations with tools such as the Active Directory Migration Tool (ADMT), run by a known service account during a planned window.

What attackers do that produces it

  • SID History injection — adding the SID of a privileged group or account to a controlled account to gain its rights while staying out of privileged group listings.

Investigation tips

  • Treat every 4765 outside a documented migration as an incident and identify the subject and source host.
  • Check whether the added SIDs belong to privileged groups (RIDs 512, 518, 519 or the Builtin Administrators SID).
  • Search 4738 and 5136 for SidHistory changes on other accounts that bypassed this event.
  • Review logons (4624, 4672) of the target account after the change.

MITRE ATT&CK techniques

TechniqueTactics
T1134.005 Access Token Manipulation: SID-History InjectionStealth, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading