Categories
Cyber Security

Deciphering Windows Event Logs: 4732

4732: A member was added to a security-enabled local group

This event can be interpreted as:

"<subjectUserName> added <memberSid> to group <targetUserName>. This action was performed from <computer>."

Helpful Hints:

To get the username of an account by SID, you can use the following command (note: this works well for local accounts, there may be a better way to do this in AD):

wmic useraccount where sid="S-1-5-21-3696241878-1170446952-3831691710-1002" get name 
Name 
SuperHacker

Leave a Reply

Your email address will not be published. Required fields are marked *