Detection of Active Directory Audit Policy Tampering
Detection of unauthorized removal of success or failure audit policies on Domain Controllers, a critical defense evasion tactic used by attackers to hide malicious activity.
This threat brief focuses on the detection of audit policy tampering on Active Directory (AD) Domain Controllers. Attackers who gain administrative access to a Domain Controller (DC) often attempt to disable audit logging to evade detection for further malicious actions, such as credential dumping, lateral movement, or persistence installation. This activity is logged in Windows Security Event Logs via EventCode 4719. Monitoring for the removal of audit policy subcategories is critical, as it serves as a high-fidelity indicator of an adversary attempting to blind security operations. If an attacker succeeds in disabling these policies, they can significantly increase their dwell time and mask their subsequent operational steps, ultimately facilitating full network compromise. Defenders should prioritize alerting on this event, as there are rarely legitimate administrative reasons to disable domain-wide audit subcategories on a production Domain Controller.
Impact
Successful tampering with audit policies on a Domain Controller prevents security teams from identifying further attacker activity, including privilege escalation and data exfiltration. This visibility gap allows adversaries to maintain persistence within the environment, potentially leading to unauthorized access to sensitive corporate data and full control over the identity infrastructure.
Recommendation
- Enable and ingest Windows EventCode 4719 from all Domain Controllers into your SIEM/centralized log management platform.
- Implement the Sigma rule below to alert on any modification to audit policy success or failure settings.
- Integrate domain controller assets into your Asset and Identities (A&I) framework to allow for targeted filtering and higher priority alerting when this event occurs on critical infrastructure.
- Establish an automated incident response playbook that triggers an immediate investigation upon any detection of EventCode 4719, as this event on a DC is rarely benign.
Immediate actions
Enable and test ingestion of Event ID 4719 in SIEM.
Threat Hunt
Search historic logs for Event ID 4719 to establish a baseline of authorized changes.
Data: Security Event Logs
Mitigations
Restrict GPO modification rights on Domain Controllers to a minimal number of Tier-0 administrators.
T1562.001
Gaps
- Audit logging needs to be configured at the Domain level to reliably capture these events.
Detection coverage 1
Detect AD Domain Controller Audit Policy Disabled
highDetects the disabling of success or failure audit policies on a Domain Controller via Windows Event ID 4719.
Detection queries are available on the platform. Get full rules →