Event ID 4794: DSRM password set attempt
- Event ID
- 4794
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4794 means
Event 4794 is written on a domain controller when an attempt is made to set the Directory Services Restore Mode (DSRM) administrator password — the local administrator account each DC keeps for offline recovery. Status is 0x0 for success; any other value is a failed attempt.
Changing this password is a rare administrative task, usually done with ntdsutil ("set dsrm password", optionally syncing from a domain account). That rarity is what makes it valuable: a known attacker persistence technique sets the DSRM password to a known value and then changes the DsrmAdminLogonBehavior registry value so the DSRM account can log on over the network while the DC runs normally, giving a backdoor local administrator on the DC.
Every 4794 should be traced to a change ticket. Correlate with registry auditing or EDR telemetry for HKLM\System\CurrentControlSet\Control\Lsa\DsrmAdminLogonBehavior.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success, Failure). Success is enabled in the default audit policy.
Only generated on domain controllers.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that attempted to set the DSRM password. |
| SubjectDomainName | Domain of that account. |
| SubjectLogonId | Logon session of the account; pivot to 4624 on the DC to see how it logged on. |
| Workstation | Computer the request came from. Equals the DC's own name when the change was made locally, e.g. with ntdsutil on the console. |
| Status | Result code; 0x0 means the password was set, anything else is a failure. |
Common benign sources
- Planned DSRM password rotation by domain administrators, typically with
ntdsutil. - DC promotion and recovery procedures that set the DSRM password.
What attackers do that produces it
- DSRM backdoor: setting a known DSRM password (sometimes synced from a controlled domain account), then enabling network logon for it via
DsrmAdminLogonBehavior. - A domain admin session from an unusual workstation changing the DSRM password on several DCs.
Investigation tips
- Confirm the change was planned; the event should be extremely rare.
- Check the DC's registry (or registry audit / EDR data) for
DsrmAdminLogonBehaviorset to 2, which allows network logons with the DSRM account. - Pivot on SubjectLogonId to the logon (4624) and look at what else that session did on the DC (4688).
- Watch for later network logons to the DC with a local account named like the DC's built-in administrator.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighPassword Change on Directory Service Restore Mode (DSRM) AccountRule by Thomas Patzke, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.