Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)

Detects Windows Security Event 4799 where checkadmin.exe targets “Administr*” accounts, consistent with admin account enumeration.

FreeReviewedSigma · High · v5
Product
windows
Service
security
Author
Florian Roth (Nextron Systems), frack113 (SigmaHQ), DRL 1.1
Published
2019-12-20
Updated
2026-07-31

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule flags Windows Security events (Event ID 4799) where the TargetUserName begins with "Administr" and the CallerProcessName ends with "\checkadmin.exe". Such activity can indicate attempts to discover or enumerate local administrator accounts, which is useful for follow-on privilege escalation and persistence. It relies on Windows Security auditing telemetry that records the caller process and the target account involved in the operation.

Related detections9 linkedT1059.001 — drag to rearrange
Windows process command lines matching May 2020 Turla ComRAT command patterns
Suspicious PowerShell Invoke-Expression with Replace Obfuscation
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Python Interpreter Launching Encoded PowerShell via subprocess
Suspicious PS1Bot PowerShell Payload Written to ProgramData (via file_event)
Suspicious Scheduled Task Running PowerShell Every Minute (via process_creation)
Malicious Non-Interactive Encoded PowerShell Stager (via process_creation)
Suspicious Hidden PowerShell Executing Substring of Dropped File
PowerShell Encoded or Download-Cradle Command Line (via process_creation)
Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)
Pivot detection · T1059.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.