Creating new objects in AD, such as user accounts, groups, organizational units (OUs), or trust relationships. Logged as Event ID 5137. Examples:
Data Collection Measures:
Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Directory Service Changes.| Name | Channel |
|---|---|
| AWS:CloudTrail | CreateAccessKey, ImportKeyPair, CreateLoginProfile, CreateKeyPair |
| azure:audit | New device object creation |
| WinEventLog:Security | Device Object Creation |
| WinEventLog:Security | EventCode=4928 |