Event ID 4781: Account renamed
- Event ID
- 4781
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4781 means
Event 4781 is written when an account's logon name (sAMAccountName) is changed. It covers user accounts — on domain controllers and on local machines — computer accounts (domain controllers only) and groups. OldTargetUserName and NewTargetUserName give the names before and after, TargetSid stays the same, and Subject* identifies who made the change.
Renames matter because many detections and reports key on names. Renaming the built-in Administrator account is a common hardening step; renaming an attacker-created account to look like a service account is a common evasion step. Always track accounts by SID.
Computer account renames are central to the noPac attack (CVE-2021-42278 / CVE-2021-42287): an attacker creates or controls a computer account, renames it to the name of a domain controller without the trailing $, requests a Kerberos ticket, then renames it back. A 4781 where NewTargetUserName matches a DC name without $ is a strong indicator.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
The rename is also visible in 4738 (users), 4742 (computers) or the group change events (4735, 4737, 4755) through the SamAccountName field.
Key fields
| Field | What it tells you |
|---|---|
| OldTargetUserName | Account name before the change. |
| NewTargetUserName | Account name after the change. For computer accounts, a new name without a trailing $ is abnormal. |
| TargetDomainName | Domain of the account, or the computer name for a local account. |
| TargetSid | SID of the renamed account — the stable identifier to follow. |
| SubjectUserName | Account that performed the rename. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Renaming the built-in Administrator or Guest account as a hardening measure (often via Group Policy).
- Name changes after marriage or naming-convention updates.
- Computers renamed by administrators, which produces 4781 for the computer account on the DC.
What attackers do that produces it
- noPac, renaming a computer account to a domain controller's name without the trailing
$to obtain a ticket for the DC. - Renaming a backdoor account to resemble a service or system account.
Investigation tips
- Alert when NewTargetUserName of a computer account lacks the trailing
$or equals the name of a domain controller. - Check who performed the rename and whether the account was created recently (4720, 4741).
- Search all events for the TargetSid to track the account under both names.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumNew or Renamed User Account with '$' CharacterRule by Ilyas Ochkov, oscd.community, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.
Related events
- 4738User account changedSecurity
- 4742Computer account changedSecurity
- 4741Computer account createdSecurity
- 4720User account createdSecurity
- 4735Local group changedSecurity
- 4737Global group changedSecurity
- 4755Universal group changedSecurity
- 4768Kerberos TGT requestedSecurity
- 4769Kerberos service ticket requestedSecurity