4706 Security log · Policy Change high severity low volume

Windows Event ID 4706 — A new trust was created to a domain

A new domain trust was created. TrustedDomainName and TrustType are key.

Why event 4706 matters

Rogue domain trust creation enables cross-domain authentication for attacker-controlled domains. Used in advanced persistence scenarios. Any unexpected trust creation is a critical indicator.

How to detect it

Alert on every occurrence. Verify with active change management — domain trusts should only be created by documented admin actions.

Log source
Security
Advanced Audit Policy — enable the 'Policy Change' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Persistence Domain Trust Modification (T1484.002)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4706   // A new trust was created to a domain
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4706
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# A new trust was created to a domain — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4706 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Policy Change events

4698 A scheduled task was created 4699 A scheduled task was deleted 4700 A scheduled task was enabled 4701 A scheduled task was disabled 4702 A scheduled task was updated 4703 A token right was adjusted 4704 A user right was assigned 4705 A user right was removed 4707 A trust to a domain was removed 4713 Kerberos policy was changed 4714 Encrypted data recovery policy was changed 4715 The audit policy (SACL) on an object was changed

Frequently asked questions

What is Windows Event ID 4706?

A new trust was created to a domain. A new domain trust was created. TrustedDomainName and TrustType are key.

Which log records event 4706?

Event 4706 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Policy Change' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 4706?

Event 4706 is associated with: Domain Trust Modification (T1484.002).

How do you detect activity around event 4706?

Alert on every occurrence. Verify with active change management — domain trusts should only be created by documented admin actions.