Windows Builtin Account Name Was Changed
The following analytic detects renaming of Windows built-in accounts via Event ID 4781. It identifies renames targeting accounts with well-known reserved RIDs (500-504): Administrator, Guest, krbtgt, DefaultAccount, and WDAGUtilityAccount, by matching the TargetSid field against the S-1-5-21-*-50[0-4] pattern. Attackers commonly rename the built-in Administrator account to evade detections that alert on the literal account name, while retaining the full privileges of the RID-500 account. Renaming Guest, krbtgt, or other reserved accounts is highly unusual in any legitimate environment.
Splunk (SPL)
