Event ID 5141: AD object deleted
- Event ID
- 5141
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Active Directory
- Default logging
- Needs configuration
What event 5141 means
Event 5141 is written on a domain controller when an audited Active Directory object is deleted. It names the object (ObjectDN, ObjectGUID, ObjectClass), the account that deleted it, and whether the deletion used the Delete Subtree control (TreeDelete), which removes an object and everything beneath it in one operation.
Deleted objects are not immediately gone: they become tombstones, or recoverable deleted objects when the AD Recycle Bin is enabled. 5141 tells you what to restore and who removed it.
Deletions of OUs, groups, GPOs or service accounts can disrupt operations. The event is also the second half of the DCShadow pattern, where rogue DC objects created under the Sites container (5137) are deleted after the malicious replication.
When it is logged
Advanced Audit Policy Configuration > DS Access > Audit Directory Service Changes (Success), applied to domain controllers, plus a SACL auditing Delete on the objects.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that deleted the object. |
| SubjectLogonId | Logon session on the DC; pivot to 4624 for the source. |
| DSName | Directory partition of the deleted object. |
| ObjectDN | Distinguished name of the object when it was deleted. |
| ObjectGUID | objectGUID; use it to find the tombstone or Recycle Bin copy and earlier 5137/5136 records. |
| ObjectClass | Class of the deleted object, e.g. user, group, organizationalUnit, groupPolicyContainer. |
| TreeDelete | Yes when the Delete Subtree control was used (the object and all its children were removed), No for a single-object delete. |
| OpCorrelationID | Links the deletion to other records from the same LDAP operation. |
Common benign sources
- Administrators removing stale users, computers, groups and GPOs.
- Identity lifecycle tools deprovisioning accounts.
- Domain controller demotion removing its server objects.
What attackers do that produces it
- Destructive deletion of OUs, groups or accounts, often with TreeDelete, to disrupt the organization.
- DCShadow cleanup, deleting the temporary server objects created under
CN=Sites,CN=Configuration. - Deleting accounts or GPOs that were created for an intrusion to cover tracks.
Investigation tips
- Prioritize TreeDelete Yes and deletions of OUs, privileged groups and GPOs.
- Search for a 5137 with the same
ObjectGUIDto spot short-lived objects. - Identify the source via
SubjectLogonIdand 4624, and restore from the Recycle Bin if needed.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.