Skip to content
Security

Event ID 4799: Local group members enumerated

A security-enabled local group membership was enumeratedSecurity event 4799 logs a process listing the members of a local group such as Administrators, with the caller process. Good signal for local admin discovery.
4799
Event ID
4799
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4799 means

Event 4799 is written when a process enumerates the members of a security-enabled local group. It names the group (TargetUserName, TargetSid), the account and session that asked (Subject*), and the process (CallerProcessName, CallerProcessId).

Attackers need to know who is a local administrator before moving laterally, and net localgroup administrators, PowerShell Get-LocalGroupMember or AD reconnaissance tools that query local admin membership of many hosts all produce 4799 on the machine being queried. Queries of Administrators (S-1-5-32-544) and Remote Desktop Users are the ones to watch.

Expect noise from Windows itself: the Volume Shadow Copy service and other built-in components enumerate local groups routinely. Baseline caller processes before alerting.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Enabled in the default audit policy.

Available on Windows 10 / Server 2016 and later. Not generated when group members are listed with the Active Directory Users and Computers snap-in.

Key fields

FieldWhat it tells you
TargetUserNameName of the group that was enumerated, e.g. Administrators.
TargetDomainNameDomain of the group; Builtin for built-in local groups.
TargetSidSID of the group. S-1-5-32-544 is Administrators, S-1-5-32-555 Remote Desktop Users, S-1-5-32-551 Backup Operators.
SubjectUserNameAccount that performed the enumeration.
SubjectLogonIdLogon session of that account; pivot to 4624 and 4688.
CallerProcessIdHexadecimal PID of the process that performed the enumeration.
CallerProcessNameFull path of that process. Built-in services (for example VSSVC.exe) are routine; net1.exe, powershell.exe or unknown binaries are worth a look.

Common benign sources

  • Volume Shadow Copy and backup software enumerating Administrators and Backup Operators.
  • Administrators opening Local Users and Groups or running inventory scripts.
  • Endpoint management agents collecting local admin membership for reporting.

What attackers do that produces it

  • Local admin discovery with net localgroup administrators or Get-LocalGroupMember after initial access.
  • Domain-wide reconnaissance tools querying local group membership on many hosts to map admin paths.

Investigation tips

  • Filter to TargetSid S-1-5-32-544 and unusual CallerProcessName values first.
  • Pivot on CallerProcessId and SubjectLogonId to 4688 for the exact command line and parent process.
  • For remote queries, the Subject is the remote account — find its type 3 logon (4624) on the same host to get the source, and check how many other hosts saw the same pattern.

MITRE ATT&CK techniques

TechniqueTactics
T1069.001 Permission Groups Discovery: Local GroupsDiscovery

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading