Quantcast
Channel: Directory Services forum
Viewing all articles
Browse latest Browse all 31638

Suspicious Computer account reset

$
0
0

Hello experts,

We are getting the multiple log with event id 4724 for many servers . I have replaced the actual name with generic names.

There are near to 20 events in 24 hours. Could somebody explain the reason of such events

Thank you.

===========================
Event Origin Details:
                Date:                      9/11/2012
                Time:                      10:04:37 AM
                Type:                      Success Audit
                Username:            
                Computer:             XXXX.XXXX.local
                Source:                  Security-Auditing
                Category:                               User Account Management
                Event ID:                                4724
                Internal Event ID: C89ED46356243
                In Work Hours:     Yes

Event Refers Administrator User : No

An attempt was made to reset an account's password.
Subject:
                Security ID:                           NT AUTHORITY\SYSTEM
                Account Name:                    <server name>$
                Account Domain:                 <domain name>
                Logon ID:                               0x3E7
Target Account:
                Security ID:                           <servername>\Administrator
                Account Name:                    Administrator
                Account Domain:                 E< server name>

============================


Viewing all articles
Browse latest Browse all 31638

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>