Loading...
Windows Events

A computer account was created

Event ID 4741 Security Audit Computer Account Management

Main fields

IP address
IP
Windows IP
ELK -
Microsoft Sentinel -
QRadar -
Splunk -
Computer name
Computer
Windows Computer
ELK winlog.computer_name
Microsoft Sentinel -
QRadar -
Splunk -
User name
SubjectUserName
Windows Subject: Account Name
ELK winlog.event_data.SubjectUserName
Microsoft Sentinel -
QRadar -
Splunk -
Important field
TargetUserName
Windows New Computer Account: Account Name
ELK winlog.event_data.TargetUserName
Microsoft Sentinel -
QRadar -
Splunk -

Fields

Windows Raw Windows ELK Microsoft Sentinel QRadar Splunk
SubjectUserSid Subject: Security ID winlog.event_data.SubjectUserSid - - -
SubjectUserName Subject: Account Name winlog.event_data.SubjectUserName - - -
SubjectDomainName Subject: Account Domain winlog.event_data.SubjectDomainName - - -
SubjectLogonId Subject: Logon ID winlog.event_data.SubjectLogonId - - -
TargetSid New Computer Account: Security ID winlog.event_data.TargetSid - - -
TargetUserName New Computer Account: Account Name winlog.event_data.TargetUserName - - -
TargetDomainName New Computer Account: Account Domain winlog.event_data.TargetDomainName - - -
SamAccountName Attributes: SAM Account Name winlog.event_data.SamAccountName - - -
DisplayName Attributes: Display Name winlog.event_data.DisplayName - - -
UserPrincipalName Attributes: User Principal Name winlog.event_data.UserPrincipalName - - -
HomeDirectory Attributes: Home Directory winlog.event_data.HomeDirectory - - -
HomePath Attributes: Home Drive winlog.event_data.HomePath - - -
ScriptPath Attributes: Script Path winlog.event_data.ScriptPath - - -
ProfilePath Attributes: Profile Path winlog.event_data.ProfilePath - - -
UserWorkstations Attributes: User Workstations winlog.event_data.UserWorkstations - - -
PasswordLastSet Attributes: Password Last Set winlog.event_data.PasswordLastSet - - -
AccountExpires Attributes: Account Expires winlog.event_data.AccountExpires - - -
PrimaryGroupId Attributes: Primary Group ID winlog.event_data.PrimaryGroupId - - -
AllowedToDelegateTo Attributes: AllowedToDelegateTo winlog.event_data.AllowedToDelegateTo - - -
OldUacValue Attributes: Old UAC Value winlog.event_data.OldUacValue - - -
NewUacValue Attributes: New UAC Value winlog.event_data.NewUacValue - - -
UserAccountControl Attributes: User Account Control winlog.event_data.UserAccountControl - - -
UserParameters Attributes: User Parameters winlog.event_data.UserParameters - - -
SidHistory Attributes: SID History winlog.event_data.SidHistory - - -
LogonHours Attributes: Logon Hours winlog.event_data.LogonHours - - -
DnsHostName Attributes: DNS Host Name winlog.event_data.DnsHostName - - -
ServicePrincipalNames Attributes: Service Principal Names winlog.event_data.ServicePrincipalNames - - -
PrivilegeList Additional Information: Privileges winlog.event_data.PrivilegeList - - -
IP System field IP System field - - - -
Computer System field Computer System field winlog.computer_name - - -
ProcessID System field ProcessID System field winlog.process.pid - - -
ThreadID System field ThreadID System field winlog.process.thread.id - - -

Sample Event

- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" /> 
  <EventID>4741</EventID> 
  <Version>0</Version> 
  <Level>0</Level> 
  <Task>13825</Task> 
  <Opcode>0</Opcode> 
  <Keywords>0x8020000000000000</Keywords> 
  <TimeCreated SystemTime="2026-08-03T10:30:53.9320568Z" /> 
  <EventRecordID>176021</EventRecordID> 
  <Correlation ActivityID="{17aef5e7-1de8-0001-e4f6-ae17e81ddd01}" /> 
  <Execution ProcessID="848" ThreadID="7460" /> 
  <Channel>Security</Channel> 
  <Computer>DC.socpedia.net</Computer> 
  <Security /> 
  </System>
- <EventData>
  <Data Name="TargetUserName">GHOSTTQHELQZJ$</Data> 
  <Data Name="TargetDomainName">SOCPEDIA</Data> 
  <Data Name="TargetSid">S-1-5-21-1838030176-2987033226-1986555923-1119</Data> 
  <Data Name="SubjectUserSid">S-1-5-21-1838030176-2987033226-1986555923-1118</Data> 
  <Data Name="SubjectUserName">user02</Data> 
  <Data Name="SubjectDomainName">SOCPEDIA</Data> 
  <Data Name="SubjectLogonId">0xdaf2ae3</Data> 
  <Data Name="PrivilegeList">SeMachineAccountPrivilege</Data> 
  <Data Name="SamAccountName">GHOSTTQHELQZJ$</Data> 
  <Data Name="DisplayName">%%1793</Data> 
  <Data Name="UserPrincipalName">-</Data> 
  <Data Name="HomeDirectory">%%1793</Data> 
  <Data Name="HomePath">%%1793</Data> 
  <Data Name="ScriptPath">%%1793</Data> 
  <Data Name="ProfilePath">%%1793</Data> 
  <Data Name="UserWorkstations">%%1793</Data> 
  <Data Name="PasswordLastSet">%%1794</Data> 
  <Data Name="AccountExpires">%%1794</Data> 
  <Data Name="PrimaryGroupId">515</Data> 
  <Data Name="AllowedToDelegateTo">-</Data> 
  <Data Name="OldUacValue">0x0</Data> 
  <Data Name="NewUacValue">0x84</Data> 
  <Data Name="UserAccountControl">%%2082 %%2087</Data> 
  <Data Name="UserParameters">%%1792</Data> 
  <Data Name="SidHistory">-</Data> 
  <Data Name="LogonHours">%%1793</Data> 
  <Data Name="DnsHostName">-</Data> 
  <Data Name="ServicePrincipalNames">-</Data> 
  </EventData>
  </Event>

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.