Skip to content
Security

Event ID 4781: Account renamed

The name of an account was changedSecurity event 4781 is logged when the sAMAccountName of a user, computer or group is changed. It gives the old and new names with the account's SID.
4781
Event ID
4781
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4781 means

Event 4781 is written when an account's logon name (sAMAccountName) is changed. It covers user accounts — on domain controllers and on local machines — computer accounts (domain controllers only) and groups. OldTargetUserName and NewTargetUserName give the names before and after, TargetSid stays the same, and Subject* identifies who made the change.

Renames matter because many detections and reports key on names. Renaming the built-in Administrator account is a common hardening step; renaming an attacker-created account to look like a service account is a common evasion step. Always track accounts by SID.

Computer account renames are central to the noPac attack (CVE-2021-42278 / CVE-2021-42287): an attacker creates or controls a computer account, renames it to the name of a domain controller without the trailing $, requests a Kerberos ticket, then renames it back. A 4781 where NewTargetUserName matches a DC name without $ is a strong indicator.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

The rename is also visible in 4738 (users), 4742 (computers) or the group change events (4735, 4737, 4755) through the SamAccountName field.

Key fields

FieldWhat it tells you
OldTargetUserNameAccount name before the change.
NewTargetUserNameAccount name after the change. For computer accounts, a new name without a trailing $ is abnormal.
TargetDomainNameDomain of the account, or the computer name for a local account.
TargetSidSID of the renamed account — the stable identifier to follow.
SubjectUserNameAccount that performed the rename.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Renaming the built-in Administrator or Guest account as a hardening measure (often via Group Policy).
  • Name changes after marriage or naming-convention updates.
  • Computers renamed by administrators, which produces 4781 for the computer account on the DC.

What attackers do that produces it

  • noPac, renaming a computer account to a domain controller's name without the trailing $ to obtain a ticket for the DC.
  • Renaming a backdoor account to resemble a service or system account.

Investigation tips

  • Alert when NewTargetUserName of a computer account lacks the trailing $ or equals the name of a domain controller.
  • Check who performed the rename and whether the account was created recently (4720, 4741).
  • Search all events for the TargetSid to track the account under both names.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation
T1068 Exploitation for Privilege EscalationPrivilege Escalation
T1036 MasqueradingStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading