4793 Security log · Account Management info severity medium volume

Windows Event ID 4793 — The Password Policy Checking API was called

Password policy was checked. SubjectUserName and Workstation are key.

Why event 4793 matters

Password spraying tools may call this API to determine password policies (lockout threshold, complexity) before launching spray attacks.

How to detect it

Alert: high volume calls from non-domain-joined or unexpected hosts. Unusual process making calls outside of normal admin tools.

Log source
Security
Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Credential Access Password Policy Discovery (T1201)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4793   // The Password Policy Checking API was called
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4793
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# The Password Policy Checking API was called — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4793 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Account Management events

4720 A user account was created 4722 A user account was enabled 4723 An attempt was made to change an account's password 4724 An attempt was made to reset an account's password 4725 A user account was disabled 4726 A user account was deleted 4728 A member was added to a security-enabled global group 4729 A member was removed from a security-enabled global group 4730 A security-enabled global group was deleted 4731 A security-enabled local group was created 4732 A member was added to a security-enabled local group 4733 A member was removed from a security-enabled local group

Frequently asked questions

What is Windows Event ID 4793?

The Password Policy Checking API was called. Password policy was checked. SubjectUserName and Workstation are key.

Which log records event 4793?

Event 4793 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 4793?

Event 4793 is associated with: Password Policy Discovery (T1201).

How do you detect activity around event 4793?

Alert: high volume calls from non-domain-joined or unexpected hosts. Unusual process making calls outside of normal admin tools.