Skip to content

Commit 1ceebdf

Browse files
Merge pull request #170 from AndrewRathbun/master
Create Security_Microsoft-Windows-Security-Auditing_4743.map
2 parents bc03e85 + 1ccdec6 commit 1ceebdf

File tree

1 file changed

+73
-0
lines changed

1 file changed

+73
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
Author: Andrew Rathbun
2+
Description: A computer account was deleted
3+
EventId: 4743
4+
Channel: Security
5+
Provider: Microsoft-Windows-Security-Auditing
6+
Maps:
7+
-
8+
Property: UserName
9+
PropertyValue: "%domain%\\%user% (%sid%)"
10+
Values:
11+
-
12+
Name: domain
13+
Value: "/Event/EventData/Data[@Name=\"SubjectDomainName\"]"
14+
-
15+
Name: user
16+
Value: "/Event/EventData/Data[@Name=\"SubjectUserName\"]"
17+
-
18+
Name: sid
19+
Value: "/Event/EventData/Data[@Name=\"SubjectUserSid\"]"
20+
-
21+
Property: PayloadData1
22+
PropertyValue: "Target: %domain%\\%user% (%sid%)"
23+
Values:
24+
-
25+
Name: domain
26+
Value: "/Event/EventData/Data[@Name=\"TargetDomainName\"]"
27+
-
28+
Name: user
29+
Value: "/Event/EventData/Data[@Name=\"TargetUserName\"]"
30+
-
31+
Name: sid
32+
Value: "/Event/EventData/Data[@Name=\"TargetUserSid\"]"
33+
-
34+
Property: PayloadData2
35+
PropertyValue: "SubjectLogonId: %SubjectLogonId%"
36+
Values:
37+
-
38+
Name: SubjectLogonId
39+
Value: "/Event/EventData/Data[@Name=\"SubjectLogonId\"]"
40+
41+
# Documentation:
42+
# https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4743
43+
# https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4743
44+
#
45+
# Example Event Data:
46+
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
47+
# <System>
48+
# <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
49+
# <EventID>4743</EventID>
50+
# <Version>0</Version>
51+
# <Level>0</Level>
52+
# <Task>13825</Task>
53+
# <Opcode>0</Opcode>
54+
# <Keywords>0x8020000000000000</Keywords>
55+
# <TimeCreated SystemTime="2015-08-14T15:57:08.104214100Z" />
56+
# <EventRecordID>172103</EventRecordID>
57+
# <Correlation />
58+
# <Execution ProcessID="520" ThreadID="1108" />
59+
# <Channel>Security</Channel>
60+
# <Computer>DC01.contoso.local</Computer>
61+
# <Security />
62+
# </System>
63+
# <EventData>
64+
# <Data Name="TargetUserName">COMPUTERACCOUNT$</Data>
65+
# <Data Name="TargetDomainName">CONTOSO</Data>
66+
# <Data Name="TargetSid">S-1-5-21-3457937927-2839227994-823803824-6118</Data>
67+
# <Data Name="SubjectUserSid">S-1-5-21-3457937927-2839227994-823803824-1104</Data>
68+
# <Data Name="SubjectUserName">dadmin</Data>
69+
# <Data Name="SubjectDomainName">CONTOSO</Data>
70+
# <Data Name="SubjectLogonId">0x3007b</Data>
71+
# <Data Name="PrivilegeList">-</Data>
72+
# </EventData>
73+
# </Event>

0 commit comments

Comments
 (0)