Event ID 4799: Local group members enumerated
- Event ID
- 4799
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4799 means
Event 4799 is written when a process enumerates the members of a security-enabled local group. It names the group (TargetUserName, TargetSid), the account and session that asked (Subject*), and the process (CallerProcessName, CallerProcessId).
Attackers need to know who is a local administrator before moving laterally, and net localgroup administrators, PowerShell Get-LocalGroupMember or AD reconnaissance tools that query local admin membership of many hosts all produce 4799 on the machine being queried. Queries of Administrators (S-1-5-32-544) and Remote Desktop Users are the ones to watch.
Expect noise from Windows itself: the Volume Shadow Copy service and other built-in components enumerate local groups routinely. Baseline caller processes before alerting.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Enabled in the default audit policy.
Available on Windows 10 / Server 2016 and later. Not generated when group members are listed with the Active Directory Users and Computers snap-in.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Name of the group that was enumerated, e.g. Administrators. |
| TargetDomainName | Domain of the group; Builtin for built-in local groups. |
| TargetSid | SID of the group. S-1-5-32-544 is Administrators, S-1-5-32-555 Remote Desktop Users, S-1-5-32-551 Backup Operators. |
| SubjectUserName | Account that performed the enumeration. |
| SubjectLogonId | Logon session of that account; pivot to 4624 and 4688. |
| CallerProcessId | Hexadecimal PID of the process that performed the enumeration. |
| CallerProcessName | Full path of that process. Built-in services (for example VSSVC.exe) are routine; net1.exe, powershell.exe or unknown binaries are worth a look. |
Common benign sources
- Volume Shadow Copy and backup software enumerating Administrators and Backup Operators.
- Administrators opening Local Users and Groups or running inventory scripts.
- Endpoint management agents collecting local admin membership for reporting.
What attackers do that produces it
- Local admin discovery with
net localgroup administratorsorGet-LocalGroupMemberafter initial access. - Domain-wide reconnaissance tools querying local group membership on many hosts to map admin paths.
Investigation tips
- Filter to TargetSid
S-1-5-32-544and unusual CallerProcessName values first. - Pivot on CallerProcessId and SubjectLogonId to 4688 for the exact command line and parent process.
- For remote queries, the Subject is the remote account — find its type 3 logon (4624) on the same host to get the source, and check how many other hosts saw the same pattern.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1069.001 Permission Groups Discovery: Local Groups | Discovery |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.