|
| 1 | +Author: Andrew Rathbun |
| 2 | +Description: A computer account was deleted |
| 3 | +EventId: 4743 |
| 4 | +Channel: Security |
| 5 | +Provider: Microsoft-Windows-Security-Auditing |
| 6 | +Maps: |
| 7 | + - |
| 8 | + Property: UserName |
| 9 | + PropertyValue: "%domain%\\%user% (%sid%)" |
| 10 | + Values: |
| 11 | + - |
| 12 | + Name: domain |
| 13 | + Value: "/Event/EventData/Data[@Name=\"SubjectDomainName\"]" |
| 14 | + - |
| 15 | + Name: user |
| 16 | + Value: "/Event/EventData/Data[@Name=\"SubjectUserName\"]" |
| 17 | + - |
| 18 | + Name: sid |
| 19 | + Value: "/Event/EventData/Data[@Name=\"SubjectUserSid\"]" |
| 20 | + - |
| 21 | + Property: PayloadData1 |
| 22 | + PropertyValue: "Target: %domain%\\%user% (%sid%)" |
| 23 | + Values: |
| 24 | + - |
| 25 | + Name: domain |
| 26 | + Value: "/Event/EventData/Data[@Name=\"TargetDomainName\"]" |
| 27 | + - |
| 28 | + Name: user |
| 29 | + Value: "/Event/EventData/Data[@Name=\"TargetUserName\"]" |
| 30 | + - |
| 31 | + Name: sid |
| 32 | + Value: "/Event/EventData/Data[@Name=\"TargetUserSid\"]" |
| 33 | + - |
| 34 | + Property: PayloadData2 |
| 35 | + PropertyValue: "SubjectLogonId: %SubjectLogonId%" |
| 36 | + Values: |
| 37 | + - |
| 38 | + Name: SubjectLogonId |
| 39 | + Value: "/Event/EventData/Data[@Name=\"SubjectLogonId\"]" |
| 40 | + |
| 41 | +# Documentation: |
| 42 | +# https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4743 |
| 43 | +# https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4743 |
| 44 | +# |
| 45 | +# Example Event Data: |
| 46 | +# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> |
| 47 | +# <System> |
| 48 | +# <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" /> |
| 49 | +# <EventID>4743</EventID> |
| 50 | +# <Version>0</Version> |
| 51 | +# <Level>0</Level> |
| 52 | +# <Task>13825</Task> |
| 53 | +# <Opcode>0</Opcode> |
| 54 | +# <Keywords>0x8020000000000000</Keywords> |
| 55 | +# <TimeCreated SystemTime="2015-08-14T15:57:08.104214100Z" /> |
| 56 | +# <EventRecordID>172103</EventRecordID> |
| 57 | +# <Correlation /> |
| 58 | +# <Execution ProcessID="520" ThreadID="1108" /> |
| 59 | +# <Channel>Security</Channel> |
| 60 | +# <Computer>DC01.contoso.local</Computer> |
| 61 | +# <Security /> |
| 62 | +# </System> |
| 63 | +# <EventData> |
| 64 | +# <Data Name="TargetUserName">COMPUTERACCOUNT$</Data> |
| 65 | +# <Data Name="TargetDomainName">CONTOSO</Data> |
| 66 | +# <Data Name="TargetSid">S-1-5-21-3457937927-2839227994-823803824-6118</Data> |
| 67 | +# <Data Name="SubjectUserSid">S-1-5-21-3457937927-2839227994-823803824-1104</Data> |
| 68 | +# <Data Name="SubjectUserName">dadmin</Data> |
| 69 | +# <Data Name="SubjectDomainName">CONTOSO</Data> |
| 70 | +# <Data Name="SubjectLogonId">0x3007b</Data> |
| 71 | +# <Data Name="PrivilegeList">-</Data> |
| 72 | +# </EventData> |
| 73 | +# </Event> |
0 commit comments