5136 Security log · DS Access high severity medium volume

Windows Event ID 5136 — A directory service object was modified

AD object attribute modified. ObjectDN, AttributeLDAPDisplayName, AttributeValue are key. Shows exactly what changed in AD.

Why event 5136 matters

AdminSDHolder modification (persistence via SDProp abuse). GPO hijacking. msDS-AllowedToDelegateTo changes (constrained delegation for persistence). userAccountControl changes (enabling DONT_REQUIRE_PREAUTH for AS-REP roasting). SPN additions to user accounts (Kerberoasting setup).

How to detect it

Alert: ObjectDN contains AdminSDHolder. Alert: AttributeLDAPDisplayName=msDS-AllowedToDelegateTo changed on user accounts. Alert: userAccountControl change adding DONT_REQUIRE_PREAUTH flag. Alert: gpLink changes on domain/OU objects.

Log source
Security
Advanced Audit Policy — enable the 'DS Access' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Persistence Account Manipulation (T1098)
Defense Evasion Group Policy Modification (T1484.001)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sigma rule
title: Sensitive AD Object Modified
status: experimental
description: Modification to sensitive AD objects including AdminSDHolder or GPOs
author: theadminstack.com
date: 2026/05/16
logsource:
    product: windows
    service: security
detection:
    selection:
        EventID: 5136
        ObjectDN|contains:
            - 'AdminSDHolder'
            - 'CN=Policies,CN=System'
    condition: selection
falsepositives:
    - Legitimate admin GPO changes
level: high
tags:
    - attack.persistence
    - attack.t1098
Sentinel / Defender KQL
SecurityEvent
| where EventID == 5136   // A directory service object was modified
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=5136
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# A directory service object was modified — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 5136 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related DS Access events

4662 An operation was performed on an object 4928 An Active Directory replica source naming context was established 4929 An Active Directory replica source naming context was removed 4930 An Active Directory replica source naming context was modified 4932 Synchronization of a replica of an Active Directory naming context has begun 4933 Synchronization of a replica of an Active Directory naming context has ended 4934 Attributes of an Active Directory object were replicated 4935 Replication failure begins 4936 Replication failure ends 4937 A lingering object was removed from the replica 5137 A directory service object was created 5138 A directory service object was undeleted

Frequently asked questions

What is Windows Event ID 5136?

A directory service object was modified. AD object attribute modified. ObjectDN, AttributeLDAPDisplayName, AttributeValue are key. Shows exactly what changed in AD.

Which log records event 5136?

Event 5136 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'DS Access' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 5136?

Event 5136 is associated with: Account Manipulation (T1098), Group Policy Modification (T1484.001).

How do you detect activity around event 5136?

Alert: ObjectDN contains AdminSDHolder. Alert: AttributeLDAPDisplayName=msDS-AllowedToDelegateTo changed on user accounts. Alert: userAccountControl change adding DONT_REQUIRE_PREAUTH flag. Alert: gpLink changes on domain/OU objects.