Skip to content
Security

Event ID 5137: AD object created

A directory service object was createdSecurity event 5137 logs the creation of an Active Directory object — user, computer, group, GPO or any other class — with its DN, class and creator.
5137
Event ID
5137
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Active Directory
Default logging
Needs configuration

What event 5137 means

Event 5137 is written on a domain controller when a new object is created in an audited container. It records the creator, the new object's ObjectDN, ObjectGUID and ObjectClass. Unlike account events such as 4720 or 4741, it covers every object class: organizational units, Group Policy containers, DNS records stored in AD, and configuration objects.

That breadth matters for detection. Creating a groupPolicyContainer shows a new GPO; creating computer objects from a regular user account shows use of the machine account quota; creating server objects under CN=Sites,CN=Configuration outside a DC promotion is a known sign of DCShadow, where an attacker briefly registers a rogue domain controller and deletes it afterwards (5141).

The attributes set at creation are not listed in 5137; related 5136 records sharing the same OpCorrelationID may carry them.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > DS Access > Audit Directory Service Changes (Success), applied to domain controllers, plus a SACL auditing Create Child on the parent containers.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that created the object.
SubjectLogonIdLogon session on the DC; pivot to 4624 for the source.
DSNameDirectory partition where the object was created.
ObjectDNDistinguished name of the new object.
ObjectGUIDobjectGUID of the new object; use it to follow later 5136 and 5141 records.
ObjectClassClass of the object, e.g. user, computer, group, organizationalUnit, groupPolicyContainer.
OpCorrelationIDLinks the creation to other records from the same LDAP operation.

Common benign sources

  • Administrators and provisioning systems creating users, groups, computers and OUs.
  • Domain joins creating computer objects.
  • New GPOs created in GPMC.
  • DC promotion creating server and NTDS Settings objects under the Sites container.

What attackers do that produces it

  • DCShadow: short-lived server or nTDSDSA objects created under CN=Sites,CN=Configuration by a host that is not being promoted, followed by their deletion.
  • Computer accounts created by a regular user through the machine account quota, used for relay or delegation attacks.
  • Creation of new GPOs or accounts for persistence.

Investigation tips

  • Filter by ObjectClass for sensitive types (computer, groupPolicyContainer, server, nTDSDSA) and review the creators.
  • Check for a matching 5141 on the same ObjectGUID soon after; create-then-delete is suspicious.
  • Pivot SubjectLogonId to 4624 on the DC to find the source workstation.

MITRE ATT&CK techniques

TechniqueTactics
T1207 Rogue Domain ControllerDefense Impairment
T1136.002 Create Account: Domain AccountPersistence
T1484.001 Domain or Tenant Policy Modification: Group Policy ModificationDefense Impairment, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading