4782 Security log · Account Management critical severity low volume

Windows Event ID 4782 — The password hash an account was accessed

Password hash accessed via Directory Replication Service. Generated during DCSync operations.

Why event 4782 matters

Generated during DCSync (Mimikatz lsadump::dcsync, Impacket secretsdump.py). An attacker with DS-Replication-Get-Changes-All right pulls all password hashes without touching LSASS. Non-DC computers generating this is a critical indicator.

How to detect it

Alert: SubjectUserName is not a DC computer account. Alert: rapid succession of 4782 events (pulling multiple hashes = full domain dump). Extremely low false-positive rate outside legitimate DC replication.

Log source
Security
Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Credential Access OS Credential Dumping: DCSync (T1003.006)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sigma rule
title: Password Hash Access — Possible DCSync
status: experimental
description: Password hash access indicating possible DCSync attack
author: theadminstack.com
date: 2026/05/16
logsource:
    product: windows
    service: security
detection:
    selection:
        EventID: 4782
    filter_dc:
        SubjectUserName|endswith: '$'
    condition: selection and not filter_dc
falsepositives:
    - Legitimate DC-to-DC replication
    - Azure AD Connect sync
level: critical
tags:
    - attack.credential_access
    - attack.t1003.006
Sentinel / Defender KQL
SecurityEvent
| where EventID == 4782   // The password hash an account was accessed
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4782
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# The password hash an account was accessed — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4782 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Account Management events

4720 A user account was created 4722 A user account was enabled 4723 An attempt was made to change an account's password 4724 An attempt was made to reset an account's password 4725 A user account was disabled 4726 A user account was deleted 4728 A member was added to a security-enabled global group 4729 A member was removed from a security-enabled global group 4730 A security-enabled global group was deleted 4731 A security-enabled local group was created 4732 A member was added to a security-enabled local group 4733 A member was removed from a security-enabled local group

Frequently asked questions

What is Windows Event ID 4782?

The password hash an account was accessed. Password hash accessed via Directory Replication Service. Generated during DCSync operations.

Which log records event 4782?

Event 4782 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 4782?

Event 4782 is associated with: OS Credential Dumping: DCSync (T1003.006).

How do you detect activity around event 4782?

Alert: SubjectUserName is not a DC computer account. Alert: rapid succession of 4782 events (pulling multiple hashes = full domain dump). Extremely low false-positive rate outside legitimate DC replication.