Skip to content
Security

Event ID 5141: AD object deleted

A directory service object was deletedSecurity event 5141 logs the deletion of an Active Directory object, with its DN, class, the account responsible and whether a subtree delete was used.
5141
Event ID
5141
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Active Directory
Default logging
Needs configuration

What event 5141 means

Event 5141 is written on a domain controller when an audited Active Directory object is deleted. It names the object (ObjectDN, ObjectGUID, ObjectClass), the account that deleted it, and whether the deletion used the Delete Subtree control (TreeDelete), which removes an object and everything beneath it in one operation.

Deleted objects are not immediately gone: they become tombstones, or recoverable deleted objects when the AD Recycle Bin is enabled. 5141 tells you what to restore and who removed it.

Deletions of OUs, groups, GPOs or service accounts can disrupt operations. The event is also the second half of the DCShadow pattern, where rogue DC objects created under the Sites container (5137) are deleted after the malicious replication.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > DS Access > Audit Directory Service Changes (Success), applied to domain controllers, plus a SACL auditing Delete on the objects.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that deleted the object.
SubjectLogonIdLogon session on the DC; pivot to 4624 for the source.
DSNameDirectory partition of the deleted object.
ObjectDNDistinguished name of the object when it was deleted.
ObjectGUIDobjectGUID; use it to find the tombstone or Recycle Bin copy and earlier 5137/5136 records.
ObjectClassClass of the deleted object, e.g. user, group, organizationalUnit, groupPolicyContainer.
TreeDeleteYes when the Delete Subtree control was used (the object and all its children were removed), No for a single-object delete.
OpCorrelationIDLinks the deletion to other records from the same LDAP operation.

Common benign sources

  • Administrators removing stale users, computers, groups and GPOs.
  • Identity lifecycle tools deprovisioning accounts.
  • Domain controller demotion removing its server objects.

What attackers do that produces it

  • Destructive deletion of OUs, groups or accounts, often with TreeDelete, to disrupt the organization.
  • DCShadow cleanup, deleting the temporary server objects created under CN=Sites,CN=Configuration.
  • Deleting accounts or GPOs that were created for an intrusion to cover tracks.

Investigation tips

  • Prioritize TreeDelete Yes and deletions of OUs, privileged groups and GPOs.
  • Search for a 5137 with the same ObjectGUID to spot short-lived objects.
  • Identify the source via SubjectLogonId and 4624, and restore from the Recycle Bin if needed.

MITRE ATT&CK techniques

TechniqueTactics
T1485 Data DestructionImpact
T1207 Rogue Domain ControllerDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading