Windows Security Event 4662: Non-Machine Account Reads Domain User Object Properties

Alert on AD user property read attempts in Windows Event 4662 from non-machine accounts.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Maxime Thiebaut (@0xThiebaut) (SigmaHQ), DRL 1.1
Published
2020-03-30
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security auditing events where a non-machine account performs read-oriented access to a domain user object, as indicated by Event ID 4662 with a user-schema object type and matching AccessMask patterns. Such targeted directory reads can enable discovery and enumeration of user objects during reconnaissance. It relies on Security event telemetry (4662) with the accessed object type and access mask fields, while excluding machine accounts and specific connector/service principals to reduce noise.

Related detections9 linkedT1087.002 — drag to rearrange
Malicious Domain Group Enumeration via NetSupport remcmdstub
Suspicious Active Directory Reconnaissance via ADExplorer or ADRecon (via process_creation)
Suspicious Service Principal Name Enumeration via Setspn by UAT-8837
Malicious Active Directory Enumeration via SharpHound or BloodHound (via process_creation)
Suspicious Group Discovery - Command (via process_creation)
SharpHound Host Enumeration Over Kerberos (via security)
SPN Enumeration Previous to Kerberoasting Attack - Native Commands (via process_creation)
Suspicious Active Directory Enumeration via AD Explorer Snapshot Process Creation
Malicious Account Added to Domain Admins Group via net Command
Windows Security Event 4662: Non-Machine Account Reads Domain User Object Properties
Pivot detection · T1087.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.