Event ID 4798: User's local groups enumerated
- Event ID
- 4798
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4798 means
Event 4798 is written when a process enumerates the security-enabled local groups a user account belongs to. It names the account that was looked up (TargetUserName, TargetSid), who did the lookup (Subject*) and the process that asked (CallerProcessName, CallerProcessId).
On its own it is very noisy: Windows components query group memberships all the time, for example when a user signs in, opens account settings or when management tools run. Its value comes from the caller: a lookup made by net.exe, PowerShell, a script host or an unknown binary, or a burst covering many accounts in a short time, points to account discovery.
The event was introduced with Windows 10 and Windows Server 2016.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled in the default audit policy.
Available on Windows 10 / Server 2016 and later. Expect high volume from built-in processes.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Account whose group membership was enumerated. |
| TargetDomainName | Domain or computer name of that account. |
| TargetSid | SID of that account. RID 500 is the built-in Administrator. |
| SubjectUserName | Account that performed the enumeration. |
| SubjectLogonId | Logon session of that account; pivot to 4624 and 4688. |
| CallerProcessId | Hexadecimal PID of the process that performed the enumeration. |
| CallerProcessName | Full path of that process. Baseline the usual Windows callers and review the rest — net1.exe, powershell.exe, script hosts or binaries outside System32. |
Common benign sources
- Built-in Windows processes checking memberships during sign-in, UAC prompts and settings pages.
- Administrators opening Computer Management or Local Users and Groups (
mmc.exe).
What attackers do that produces it
- Local account discovery with
net user <name>, PowerShellGet-LocalGroup*cmdlets or post-exploitation frameworks. - A single session enumerating many accounts in quick succession, typical of automated reconnaissance.
Investigation tips
- Exclude known callers from your baseline, then group by CallerProcessName and SubjectUserName.
- Pivot on CallerProcessId and SubjectLogonId to 4688 to get the command line and the parent process that started the enumeration.
- Look for the same session also triggering 4799 (group member enumeration) — together they show broader discovery.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1087.001 Account Discovery: Local Account | Discovery |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.