Windows Security Events: SID History Added to Active Directory Object

Flags Windows Security events indicating Active Directory SIDHistory changes that can grant additional privileges.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Thomas Patzke, @atc_project (improvements) (SigmaHQ), DRL 1.1
Published
2017-02-19
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Active Directory changes involving the SIDHistory attribute, using Windows Security audit events that record account modifications. Attackers can abuse SID history to retain or gain effective access in a different domain, supporting persistence and privilege escalation. The detection relies on Event IDs 4765 or 4766 in conjunction with 4738, and checks for specific SIDHistory values while excluding cases where SIDHistory is null or matches the defined non-suspicious pattern.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.