name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 version: 4 creation_date: '2024-05-22' modification_date: '2026-05-13' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: - Group Modification - Group Metadata - User Account Metadata - Active Directory Object Modification source: XmlWinEventLog:System sourcetype: XmlWinEventLog separator: EventCode separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 version: 10.0.1 fields: - _time - Account_Domain - Account_Name - CategoryString - ComputerName - Error_Code - EventCode - EventType - Keywords - LogName - Logon_ID - Message - OpCode - RecordNumber - Security_ID - SourceName - Subject_Account_Domain - Subject_Account_Name - Subject_Logon_ID - Subject_Security_ID - Target_Account_Domain - Target_Account_Name - Target_Security_ID - TaskCategory - Type - action - app - body - category - change_type - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dest - dest_nt_domain - dest_nt_host - dvc - dvc_nt_host - event_id - eventtype - host - id - index - linecount - member_dn - member_id - member_nt_domain - msad_action - name - object - object_attrs - object_category - object_id - product - punct - result - session_id - severity - severity_id - signature - signature_id - source - sourcetype - splunk_server - src_nt_domain - src_user - src_user_name - status - subject - ta_windows_action - ta_windows_security_CategoryString - tag - tag::eventtype - timeendpos - timestartpos - user - user_group - user_name - vendor - vendor_product output_fields: - dest