Skip to content
Security

Event ID 5136: AD object modified

A directory service object was modifiedSecurity event 5136 logs an attribute change on an Active Directory object, with the attribute and value — GPO edits, SPNs, ACLs, shadow credentials.
5136
Event ID
5136
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Active Directory
Default logging
Needs configuration

What event 5136 means

Event 5136 is written on a domain controller when an attribute of an audited Active Directory object is modified. Each record names the object (ObjectDN, ObjectClass, ObjectGUID), the attribute (AttributeLDAPDisplayName), the value and whether the value was added or deleted. A replaced value usually appears as two records — Value Deleted with the old value, then Value Added with the new one — sharing the same OpCorrelationID.

Because it carries the actual values, 5136 is the best native record of AD tampering. Attributes worth alerting on include nTSecurityDescriptor (permission changes such as granting replication rights), gPCFileSysPath and gPCMachineExtensionNames on Group Policy objects, servicePrincipalName (setting an SPN to Kerberoast an account), msDS-KeyCredentialLink (shadow credentials), msDS-AllowedToActOnBehalfOfOtherIdentity (resource-based constrained delegation), sIDHistory and member.

Coverage depends on SACLs: only attributes and objects covered by an auditing ACE are logged.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > DS Access > Audit Directory Service Changes (Success), applied to domain controllers, plus SACLs on the objects and attributes to audit.

Only logged on domain controllers, by the DC that processed the change. Collect from every DC. Changes made through replication from another DC are logged on the originating DC.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change.
SubjectLogonIdLogon session on the DC; pivot to 4624 for the source IP.
DSNameName of the directory partition (domain) that was modified.
ObjectDNDistinguished name of the modified object.
ObjectGUIDobjectGUID of the object; stable across renames and moves.
ObjectClassClass of the object, e.g. user, computer, group, groupPolicyContainer, domainDNS.
AttributeLDAPDisplayNameLDAP name of the modified attribute, e.g. servicePrincipalName, msDS-KeyCredentialLink, nTSecurityDescriptor, gPCFileSysPath, member.
AttributeSyntaxOIDSyntax OID of the attribute (how the value is encoded).
AttributeValueThe value added or deleted. For nTSecurityDescriptor this is SDDL.
OperationTypeWhether the value was added or removed.
ValueMeaning
%%14674Value Added — the new value.
%%14675Value Deleted — the previous value, typically part of a change.
OpCorrelationIDGroups all 5136, 5137 and 5141 records belonging to the same LDAP operation.
AppCorrelationIDApplication correlation ID; often empty.

Common benign sources

  • Administrators editing users, groups and GPOs through ADUC, GPMC or PowerShell.
  • Identity management and HR provisioning systems updating attributes at scale.
  • Windows Hello for Business and device registration writing msDS-KeyCredentialLink for users and computers as part of normal enrollment.
  • Service installations registering servicePrincipalName values on their accounts.

What attackers do that produces it

  • Shadow credentials: a new msDS-KeyCredentialLink value on a user or computer written by an account other than the normal enrollment service, enabling PKINIT authentication as that target.
  • Targeted Kerberoasting by adding a servicePrincipalName to a user account, then removing it.
  • Resource-based constrained delegation: writing msDS-AllowedToActOnBehalfOfOtherIdentity on a computer object to impersonate users to it.
  • GPO abuse via changes to gPCFileSysPath, gPCMachineExtensionNames or versionNumber of a Group Policy object.
  • nTSecurityDescriptor changes on the domain root or AdminSDHolder granting DCSync or full-control rights.
  • sIDHistory values added to give an account a privileged SID.

Investigation tips

  • Group records by OpCorrelationID and compare the Value Deleted / Value Added pair to see before and after.
  • Alert on the sensitive attribute list above when the subject is not a known admin or service.
  • For nTSecurityDescriptor, decode the SDDL and look for new ACEs with replication GUIDs or GenericAll.
  • Pivot SubjectLogonId to the DC's 4624 to find the workstation the change came from.

MITRE ATT&CK techniques

TechniqueTactics
T1484.001 Domain or Tenant Policy Modification: Group Policy ModificationDefense Impairment, Privilege Escalation
T1098 Account ManipulationPersistence, Privilege Escalation
T1558.003 Steal or Forge Kerberos Tickets: KerberoastingCredential Access
T1134.005 Access Token Manipulation: SID-History InjectionStealth, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

10 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 6
  • Medium · 4

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideActive Directory changes: Event ID 5136 and DCSync (4662)

Sources and further reading