Object deletion in AD (e.g., user accounts, groups, OUs) is logged as Event ID 5141. Examples:
Data Collection Measures:
Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Directory Service Changes.| Name | Channel |
|---|---|
| WinEventLog:DirectoryService | EventCode=4929 |
| ID | Name | Technique Detected |
|---|---|---|
| DET0594 | Detection of Unauthorized DCSync Operations via Replication API Abuse | T1003.006 |