Skip to content
Security

Event ID 4798: User's local groups enumerated

A user's local group membership was enumeratedSecurity event 4798 logs a process listing which local groups a user belongs to, with the calling process. Mostly noise, but useful for spotting discovery.
4798
Event ID
4798
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4798 means

Event 4798 is written when a process enumerates the security-enabled local groups a user account belongs to. It names the account that was looked up (TargetUserName, TargetSid), who did the lookup (Subject*) and the process that asked (CallerProcessName, CallerProcessId).

On its own it is very noisy: Windows components query group memberships all the time, for example when a user signs in, opens account settings or when management tools run. Its value comes from the caller: a lookup made by net.exe, PowerShell, a script host or an unknown binary, or a burst covering many accounts in a short time, points to account discovery.

The event was introduced with Windows 10 and Windows Server 2016.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled in the default audit policy.

Available on Windows 10 / Server 2016 and later. Expect high volume from built-in processes.

Key fields

FieldWhat it tells you
TargetUserNameAccount whose group membership was enumerated.
TargetDomainNameDomain or computer name of that account.
TargetSidSID of that account. RID 500 is the built-in Administrator.
SubjectUserNameAccount that performed the enumeration.
SubjectLogonIdLogon session of that account; pivot to 4624 and 4688.
CallerProcessIdHexadecimal PID of the process that performed the enumeration.
CallerProcessNameFull path of that process. Baseline the usual Windows callers and review the rest — net1.exe, powershell.exe, script hosts or binaries outside System32.

Common benign sources

  • Built-in Windows processes checking memberships during sign-in, UAC prompts and settings pages.
  • Administrators opening Computer Management or Local Users and Groups (mmc.exe).

What attackers do that produces it

  • Local account discovery with net user <name>, PowerShell Get-LocalGroup* cmdlets or post-exploitation frameworks.
  • A single session enumerating many accounts in quick succession, typical of automated reconnaissance.

Investigation tips

  • Exclude known callers from your baseline, then group by CallerProcessName and SubjectUserName.
  • Pivot on CallerProcessId and SubjectLogonId to 4688 to get the command line and the parent process that started the enumeration.
  • Look for the same session also triggering 4799 (group member enumeration) — together they show broader discovery.

MITRE ATT&CK techniques

TechniqueTactics
T1087.001 Account Discovery: Local AccountDiscovery

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading