Event ID 5137: AD object created
- Event ID
- 5137
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Active Directory
- Default logging
- Needs configuration
What event 5137 means
Event 5137 is written on a domain controller when a new object is created in an audited container. It records the creator, the new object's ObjectDN, ObjectGUID and ObjectClass. Unlike account events such as 4720 or 4741, it covers every object class: organizational units, Group Policy containers, DNS records stored in AD, and configuration objects.
That breadth matters for detection. Creating a groupPolicyContainer shows a new GPO; creating computer objects from a regular user account shows use of the machine account quota; creating server objects under CN=Sites,CN=Configuration outside a DC promotion is a known sign of DCShadow, where an attacker briefly registers a rogue domain controller and deletes it afterwards (5141).
The attributes set at creation are not listed in 5137; related 5136 records sharing the same OpCorrelationID may carry them.
When it is logged
Advanced Audit Policy Configuration > DS Access > Audit Directory Service Changes (Success), applied to domain controllers, plus a SACL auditing Create Child on the parent containers.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that created the object. |
| SubjectLogonId | Logon session on the DC; pivot to 4624 for the source. |
| DSName | Directory partition where the object was created. |
| ObjectDN | Distinguished name of the new object. |
| ObjectGUID | objectGUID of the new object; use it to follow later 5136 and 5141 records. |
| ObjectClass | Class of the object, e.g. user, computer, group, organizationalUnit, groupPolicyContainer. |
| OpCorrelationID | Links the creation to other records from the same LDAP operation. |
Common benign sources
- Administrators and provisioning systems creating users, groups, computers and OUs.
- Domain joins creating computer objects.
- New GPOs created in GPMC.
- DC promotion creating server and NTDS Settings objects under the Sites container.
What attackers do that produces it
- DCShadow: short-lived server or
nTDSDSAobjects created underCN=Sites,CN=Configurationby a host that is not being promoted, followed by their deletion. - Computer accounts created by a regular user through the machine account quota, used for relay or delegation attacks.
- Creation of new GPOs or accounts for persistence.
Investigation tips
- Filter by
ObjectClassfor sensitive types (computer, groupPolicyContainer, server, nTDSDSA) and review the creators. - Check for a matching 5141 on the same
ObjectGUIDsoon after; create-then-delete is suspicious. - Pivot
SubjectLogonIdto 4624 on the DC to find the source workstation.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighPotential Kerberos Coercion by Spoofing SPNs via DNS ManipulationRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.