Event ID 5136: AD object modified
- Event ID
- 5136
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Active Directory
- Default logging
- Needs configuration
What event 5136 means
Event 5136 is written on a domain controller when an attribute of an audited Active Directory object is modified. Each record names the object (ObjectDN, ObjectClass, ObjectGUID), the attribute (AttributeLDAPDisplayName), the value and whether the value was added or deleted. A replaced value usually appears as two records — Value Deleted with the old value, then Value Added with the new one — sharing the same OpCorrelationID.
Because it carries the actual values, 5136 is the best native record of AD tampering. Attributes worth alerting on include nTSecurityDescriptor (permission changes such as granting replication rights), gPCFileSysPath and gPCMachineExtensionNames on Group Policy objects, servicePrincipalName (setting an SPN to Kerberoast an account), msDS-KeyCredentialLink (shadow credentials), msDS-AllowedToActOnBehalfOfOtherIdentity (resource-based constrained delegation), sIDHistory and member.
Coverage depends on SACLs: only attributes and objects covered by an auditing ACE are logged.
When it is logged
Advanced Audit Policy Configuration > DS Access > Audit Directory Service Changes (Success), applied to domain controllers, plus SACLs on the objects and attributes to audit.
Only logged on domain controllers, by the DC that processed the change. Collect from every DC. Changes made through replication from another DC are logged on the originating DC.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that made the change. | ||||||
| SubjectLogonId | Logon session on the DC; pivot to 4624 for the source IP. | ||||||
| DSName | Name of the directory partition (domain) that was modified. | ||||||
| ObjectDN | Distinguished name of the modified object. | ||||||
| ObjectGUID | objectGUID of the object; stable across renames and moves. | ||||||
| ObjectClass | Class of the object, e.g. user, computer, group, groupPolicyContainer, domainDNS. | ||||||
| AttributeLDAPDisplayName | LDAP name of the modified attribute, e.g. servicePrincipalName, msDS-KeyCredentialLink, nTSecurityDescriptor, gPCFileSysPath, member. | ||||||
| AttributeSyntaxOID | Syntax OID of the attribute (how the value is encoded). | ||||||
| AttributeValue | The value added or deleted. For nTSecurityDescriptor this is SDDL. | ||||||
| OperationType | Whether the value was added or removed.
| ||||||
| OpCorrelationID | Groups all 5136, 5137 and 5141 records belonging to the same LDAP operation. | ||||||
| AppCorrelationID | Application correlation ID; often empty. |
Common benign sources
- Administrators editing users, groups and GPOs through ADUC, GPMC or PowerShell.
- Identity management and HR provisioning systems updating attributes at scale.
- Windows Hello for Business and device registration writing
msDS-KeyCredentialLinkfor users and computers as part of normal enrollment. - Service installations registering
servicePrincipalNamevalues on their accounts.
What attackers do that produces it
- Shadow credentials: a new
msDS-KeyCredentialLinkvalue on a user or computer written by an account other than the normal enrollment service, enabling PKINIT authentication as that target. - Targeted Kerberoasting by adding a
servicePrincipalNameto a user account, then removing it. - Resource-based constrained delegation: writing
msDS-AllowedToActOnBehalfOfOtherIdentityon a computer object to impersonate users to it. - GPO abuse via changes to
gPCFileSysPath,gPCMachineExtensionNamesorversionNumberof a Group Policy object. nTSecurityDescriptorchanges on the domain root or AdminSDHolder granting DCSync or full-control rights.sIDHistoryvalues added to give an account a privileged SID.
Investigation tips
- Group records by
OpCorrelationIDand compare the Value Deleted / Value Added pair to see before and after. - Alert on the sensitive attribute list above when the subject is not a known admin or service.
- For
nTSecurityDescriptor, decode the SDDL and look for new ACEs with replication GUIDs or GenericAll. - Pivot
SubjectLogonIdto the DC's 4624 to find the workstation the change came from.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1484.001 Domain or Tenant Policy Modification: Group Policy Modification | Defense Impairment, Privilege Escalation |
| T1098 Account Manipulation | Persistence, Privilege Escalation |
| T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting | Credential Access |
| T1134.005 Access Token Manipulation: SID-History Injection | Stealth, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
10 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 6
- Medium · 4
- HighActive Directory User BackdoorsRule by @neu5ron, SigmaHQ, DRL 1.1
- HighPersistence and Execution at Scale via GPO Scheduled TaskRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- HighPossible Shadow Credentials AddedRule by Nasreddine Bencherchali (Nextron Systems), Elastic (idea), SigmaHQ, DRL 1.1
- HighPotential Kerberos Coercion by Spoofing SPNs via DNS ManipulationRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighPowerview Add-DomainObjectAcl DCSync AD Extend RightRule by Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, SigmaHQ, DRL 1.1
- HighSuspicious LDAP-Attributes UsedRule by xknow @xknow_infosec, SigmaHQ, DRL 1.1
- MediumGroup Policy Abuse for Privilege AdditionRule by Elastic, Josh Nickels, Marius Rothenbücher, SigmaHQ, DRL 1.1
- MediumPossible DC Shadow AttackRule by Ilyas Ochkov, oscd.community, Chakib Gzenayi (@Chak092), Hosni Mribah, SigmaHQ, DRL 1.1
- MediumStartup/Logon Script Added to Group Policy ObjectRule by Elastic, Josh Nickels, Marius Rothenbücher, SigmaHQ, DRL 1.1
- MediumWindows Default Domain GPO ModificationRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.