Skip to content
Threat Feed
high advisory

Detection of Windows Audit Policy Tampering via Event ID 4719

Adversaries may disable critical Windows audit policies to evade detection by monitoring tools, an activity identifiable through the analysis of Event ID 4719.

Attackers who gain administrative access to a host, particularly domain controllers, often seek to disable security auditing to mask their post-exploitation activities. This technique allows adversaries to perform actions like privilege escalation, lateral movement, or data exfiltration without generating logs that would alert defenders. This detection focuses on Windows Security Event ID 4719, which is generated when a system audit policy is changed. Defenders should monitor for instances where success or failure auditing for critical subcategories is removed. Because these changes are rare in a well-managed production environment, they serve as high-fidelity indicators of potential compromise or insider threat activity.

Impact

Successful tampering with audit policies allows an attacker to operate undetected, leading to significant risks such as full domain compromise, undetected persistence, and unauthorized data access. If an attacker disables audit policies, the SOC may lose visibility into the entire attack lifecycle, preventing effective incident response and forensic investigation.

Recommendation

  • Enable the "Audit Audit Policy Change" subcategory in your Group Policy settings to ensure Windows records these modifications.
  • Implement log ingestion for Windows Security Event ID 4719 across all endpoints and domain controllers.
  • Establish a baseline of legitimate audit policy changes in your environment to tune the detection logic and suppress false positives from legitimate administrative tasks.
  • Deploy the provided detection logic to monitor for removals of critical subcategories identified by your security team.

Immediate actions

Enable 'Audit Audit Policy Change' subcategory via GPO.

IT Operations 72h

Threat Hunt

Search for Event ID 4719 in historical logs.

T1562.002 medium high confidence hunt now

Data: Windows Event Logs

Mitigations

Restrict administrative access to GPO and audit policy configuration.

medium IT Operations

T1562.002

Detection coverage 1

Detect Disabling of Important Windows Audit Policies

high

Detects when critical success or failure audit policies are disabled on a Windows system by monitoring Event ID 4719.

sigma tactics: defense_evasion techniques: T1562.002 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →