Skip to content
Security

Event ID 4964: Special group logon

Special groups have been assigned to a new logonSecurity event 4964 flags a logon by a member of a group listed in the SpecialGroups registry value, e.g. Domain Admins. Only works once configured.
4964
Event ID
4964
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Needs configuration

What event 4964 means

Event 4964 is written when an account that belongs to one of the administrator-defined Special Groups logs on. The list of groups is a semicolon-separated string of SIDs stored in the SpecialGroups value under HKLM\System\CurrentControlSet\Control\Lsa\Audit. When a new logon's token contains any of them, Windows writes 4964 alongside the usual 4624, with the matching SIDs in SidList.

It is a cheap, built-in way to alert on privileged logons where they should not happen — Domain Admins signing in to ordinary workstations, service account groups logging on interactively. Because the list is local to each machine, it is normally deployed by Group Policy registry preferences to the hosts where such logons are forbidden.

With no SpecialGroups value configured, the event never fires, even though its audit subcategory is on by default.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Special Logon (Success), plus the SpecialGroups string value (semicolon-separated group SIDs) under HKLM\System\CurrentControlSet\Control\Lsa\Audit.

Audit Special Logon is enabled for Success by default, but nothing is logged until the registry value is set.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that requested the logon on the local machine, often the computer account.
TargetUserNameAccount that logged on and matched a special group.
TargetDomainNameDomain of that account.
TargetUserSidSID of that account.
TargetLogonIdNew logon session. Pivot to the 4624 with the same TargetLogonId for LogonType and source address.
TargetLogonGuidLogon GUID; can be matched to 4769 on a domain controller and to 4624/4648 on this host.
SidListThe special group SIDs found in the new logon's token, e.g. the Domain Admins SID (RID 512).

Common benign sources

  • Administrators logging on to servers or admin workstations where privileged access is expected.
  • Service accounts in a monitored group starting their services (logon type 5).

What attackers do that produces it

  • Stolen Domain Admin credentials used on a regular workstation or server outside the tier they belong to — a classic lateral movement indicator.
  • Privileged accounts logging on at unusual times or from unusual source addresses.

Investigation tips

  • Join each 4964 to its 4624 via TargetLogonId to get LogonType, IpAddress and WorkstationName.
  • Check whether this host is one where members of the listed groups should ever log on.
  • Follow the session with 4672 and 4688 (same logon ID) to see what the privileged account did.

MITRE ATT&CK techniques

TechniqueTactics
T1078.002 Valid Accounts: Domain AccountsStealth, Persistence, Privilege Escalation, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading