Event ID 4767: Account unlocked
- Event ID
- 4767
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4767 means
Event 4767 is written when a locked-out account is unlocked — on domain controllers for domain accounts and on member servers and workstations for local accounts. Subject* identifies who unlocked the account and Target* the account that was unlocked.
It usually closes a lockout story: 4740 (locked), then 4767 (unlocked by the helpdesk), often with a 4724 password reset. Reading these three events together tells you how long the account was unavailable and who restored access.
Because unlocking re-enables authentication, an unlock by an unexpected account, or right after a burst of failed logons from an unknown source, lets an attacker continue guessing or use a password they have obtained.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that unlocked the target account. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| TargetUserName | Account that was unlocked. |
| TargetDomainName | Domain of the unlocked account, or the computer name for a local account. |
| TargetSid | SID of the unlocked account. |
Common benign sources
- Helpdesk unlocking a user after a lockout, often together with a password reset (4724).
- Self-service password reset tools unlocking accounts on behalf of users.
What attackers do that produces it
- Unlocking an account locked by password guessing so the attack can continue, or so a compromised password can be used.
Investigation tips
- Match the unlock with the preceding 4740 for the same TargetSid and review the lockout's caller computer.
- Verify that SubjectUserName is a helpdesk or self-service account and that the user requested it.
- Look for a logon by the target (4624) soon after the unlock and check its source.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.