Skip to content
Threat Feed
high advisory

Detection of Active Directory Audit Policy Tampering

Detection of unauthorized removal of success or failure audit policies on Domain Controllers, a critical defense evasion tactic used by attackers to hide malicious activity.

This threat brief focuses on the detection of audit policy tampering on Active Directory (AD) Domain Controllers. Attackers who gain administrative access to a Domain Controller (DC) often attempt to disable audit logging to evade detection for further malicious actions, such as credential dumping, lateral movement, or persistence installation. This activity is logged in Windows Security Event Logs via EventCode 4719. Monitoring for the removal of audit policy subcategories is critical, as it serves as a high-fidelity indicator of an adversary attempting to blind security operations. If an attacker succeeds in disabling these policies, they can significantly increase their dwell time and mask their subsequent operational steps, ultimately facilitating full network compromise. Defenders should prioritize alerting on this event, as there are rarely legitimate administrative reasons to disable domain-wide audit subcategories on a production Domain Controller.

Impact

Successful tampering with audit policies on a Domain Controller prevents security teams from identifying further attacker activity, including privilege escalation and data exfiltration. This visibility gap allows adversaries to maintain persistence within the environment, potentially leading to unauthorized access to sensitive corporate data and full control over the identity infrastructure.

Recommendation

  1. Enable and ingest Windows EventCode 4719 from all Domain Controllers into your SIEM/centralized log management platform.
  2. Implement the Sigma rule below to alert on any modification to audit policy success or failure settings.
  3. Integrate domain controller assets into your Asset and Identities (A&I) framework to allow for targeted filtering and higher priority alerting when this event occurs on critical infrastructure.
  4. Establish an automated incident response playbook that triggers an immediate investigation upon any detection of EventCode 4719, as this event on a DC is rarely benign.

Immediate actions

Enable and test ingestion of Event ID 4719 in SIEM.

Detection Engineering 48h

Threat Hunt

Search historic logs for Event ID 4719 to establish a baseline of authorized changes.

T1562.001 high high confidence hunt now

Data: Security Event Logs

Mitigations

Restrict GPO modification rights on Domain Controllers to a minimal number of Tier-0 administrators.

immediate IT Operations

T1562.001

Gaps

  • Audit logging needs to be configured at the Domain level to reliably capture these events.

Detection coverage 1

Detect AD Domain Controller Audit Policy Disabled

high

Detects the disabling of success or failure audit policies on a Domain Controller via Windows Event ID 4719.

sigma tactics: defense_evasion techniques: T1562.001 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →