Detection of Windows Audit Policy Tampering via Event ID 4719
Adversaries may disable critical Windows audit policies to evade detection by monitoring tools, an activity identifiable through the analysis of Event ID 4719.
Attackers who gain administrative access to a host, particularly domain controllers, often seek to disable security auditing to mask their post-exploitation activities. This technique allows adversaries to perform actions like privilege escalation, lateral movement, or data exfiltration without generating logs that would alert defenders. This detection focuses on Windows Security Event ID 4719, which is generated when a system audit policy is changed. Defenders should monitor for instances where success or failure auditing for critical subcategories is removed. Because these changes are rare in a well-managed production environment, they serve as high-fidelity indicators of potential compromise or insider threat activity.
Impact
Successful tampering with audit policies allows an attacker to operate undetected, leading to significant risks such as full domain compromise, undetected persistence, and unauthorized data access. If an attacker disables audit policies, the SOC may lose visibility into the entire attack lifecycle, preventing effective incident response and forensic investigation.
Recommendation
- Enable the "Audit Audit Policy Change" subcategory in your Group Policy settings to ensure Windows records these modifications.
- Implement log ingestion for Windows Security Event ID 4719 across all endpoints and domain controllers.
- Establish a baseline of legitimate audit policy changes in your environment to tune the detection logic and suppress false positives from legitimate administrative tasks.
- Deploy the provided detection logic to monitor for removals of critical subcategories identified by your security team.
Immediate actions
Enable 'Audit Audit Policy Change' subcategory via GPO.
Threat Hunt
Search for Event ID 4719 in historical logs.
Data: Windows Event Logs
Mitigations
Restrict administrative access to GPO and audit policy configuration.
T1562.002
Detection coverage 1
Detect Disabling of Important Windows Audit Policies
highDetects when critical success or failure audit policies are disabled on a Windows system by monitoring Event ID 4719.
Detection queries are available on the platform. Get full rules →