Windows: Detect Computer Account Rename to Non-Standard Name Missing Trailing '$'

Alerts on Windows 4781 computer account renames where the new name lacks the '$' suffix.

FreeReviewedSigma · High · v5
Product
windows
Service
security
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-12-22
Updated
2026-07-31

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Security event 4781 where an existing computer account is renamed such that the new account name does not contain a '$' character. Attackers may abuse computer account name spoofing to support stealthy persistence and privilege escalation behaviors associated with SAM account naming misuse. It relies on Windows Security auditing for account rename events and the old/new target account name fields captured in the event telemetry.

Related detections9 linkedT1036 — drag to rearrange
Renamed Computer Account Renamed Without a Trailing $ - CVE-2021-42278/42287 (via security)
Suspicious Rclone Exfiltration Masquerading as wininit.exe
Suspicious Executable Running from Public Pictures Directory
Suspicious Python Execution via Renamed Synaptics Binary
Agent Tesla Persistence via Realtek Named Scheduled Task Batch
Suspicious Interlock Fake Updater Executable Execution
Malicious Cluster-Admin Role Binding Creation (via audit)
Malicious User Password Change Using Current Hash Password - ChangeNTLM - Mimikatz (via security)
Suspicious Account Password Set to Never Expire. (via security)
Windows: Detect Computer Account Rename to Non-Standard Name Missing Trailing '$'
Pivot detection · T1036 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.