4780 Security log · Account Management medium severity low volume

Windows Event ID 4780 — The ACL was set on accounts which are members of administrators groups

ACL set on admin account by AdminSDHolder SDProp process. Fires hourly for protected accounts.

Why event 4780 matters

AdminSDHolder manipulation grants persistent privileged access that survives typical cleanup. SDProp runs hourly resetting ACLs — 4780 fires each time. Attackers modify AdminSDHolder to persist.

How to detect it

Alert: SubjectUserName is not SYSTEM. Normal: SYSTEM applies ACLs during SDProp. Abnormal: any other account modifying admin ACLs.

Log source
Security
Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Persistence OS Credential Dumping (T1003)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4780   // The ACL was set on accounts which are members of administrators groups
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4780
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# The ACL was set on accounts which are members of administrators groups — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4780 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Account Management events

4720 A user account was created 4722 A user account was enabled 4723 An attempt was made to change an account's password 4724 An attempt was made to reset an account's password 4725 A user account was disabled 4726 A user account was deleted 4728 A member was added to a security-enabled global group 4729 A member was removed from a security-enabled global group 4730 A security-enabled global group was deleted 4731 A security-enabled local group was created 4732 A member was added to a security-enabled local group 4733 A member was removed from a security-enabled local group

Frequently asked questions

What is Windows Event ID 4780?

The ACL was set on accounts which are members of administrators groups. ACL set on admin account by AdminSDHolder SDProp process. Fires hourly for protected accounts.

Which log records event 4780?

Event 4780 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 4780?

Event 4780 is associated with: OS Credential Dumping (T1003).

How do you detect activity around event 4780?

Alert: SubjectUserName is not SYSTEM. Normal: SYSTEM applies ACLs during SDProp. Abnormal: any other account modifying admin ACLs.