diff --git a/evtx/Maps/Security_Microsoft-Windows-Security-Auditing_4743.map b/evtx/Maps/Security_Microsoft-Windows-Security-Auditing_4743.map new file mode 100644 index 00000000..061f8080 --- /dev/null +++ b/evtx/Maps/Security_Microsoft-Windows-Security-Auditing_4743.map @@ -0,0 +1,73 @@ +Author: Andrew Rathbun +Description: A computer account was deleted +EventId: 4743 +Channel: Security +Provider: Microsoft-Windows-Security-Auditing +Maps: + - + Property: UserName + PropertyValue: "%domain%\\%user% (%sid%)" + Values: + - + Name: domain + Value: "/Event/EventData/Data[@Name=\"SubjectDomainName\"]" + - + Name: user + Value: "/Event/EventData/Data[@Name=\"SubjectUserName\"]" + - + Name: sid + Value: "/Event/EventData/Data[@Name=\"SubjectUserSid\"]" + - + Property: PayloadData1 + PropertyValue: "Target: %domain%\\%user% (%sid%)" + Values: + - + Name: domain + Value: "/Event/EventData/Data[@Name=\"TargetDomainName\"]" + - + Name: user + Value: "/Event/EventData/Data[@Name=\"TargetUserName\"]" + - + Name: sid + Value: "/Event/EventData/Data[@Name=\"TargetUserSid\"]" + - + Property: PayloadData2 + PropertyValue: "SubjectLogonId: %SubjectLogonId%" + Values: + - + Name: SubjectLogonId + Value: "/Event/EventData/Data[@Name=\"SubjectLogonId\"]" + +# Documentation: +# https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4743 +# https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4743 +# +# Example Event Data: +# +# +# +# 4743 +# 0 +# 0 +# 13825 +# 0 +# 0x8020000000000000 +# +# 172103 +# +# +# Security +# DC01.contoso.local +# +# +# +# COMPUTERACCOUNT$ +# CONTOSO +# S-1-5-21-3457937927-2839227994-823803824-6118 +# S-1-5-21-3457937927-2839227994-823803824-1104 +# dadmin +# CONTOSO +# 0x3007b +# - +# +#