Hub
Identity

Active Directory audit

About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/windows-active-directory/generator.yml \
  --id ad \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
4768Kerberos TGT issued47% of authenticationauthentication
4769Service ticket issued45% of authenticationauthentication
4776NTLM validation6% of authenticationauthentication
4771Kerberos pre-authentication failed2% of authenticationauthentication
4728Temporary global-group grantAbout 12/dayiam
4729Temporary grant removedPer grant after 20–40 minutesiam
5136Directory attribute replacedAbout six pairs/dayconfiguration

Realism Features

  • Human office hours and twelve continuous monitoring accounts
  • Every modeled grant ends after 20–40 minutes in both modes
  • Selected ECS projection; version 2 Kerberos profile assumes patched servers and RC4-enabled service accounts

Sample Output

{
  "@timestamp": "2026-09-01T07:02:05.777167+00:00",
  "agent": {
    "ephemeral_id": "943942bd-09ec-48aa-957d-2f12ecb83866",
    "id": "a51465f9-72f4-4761-89bb-55de00ec6701",
    "name": "dc01.contoso.local",
    "type": "filebeat",
    "version": "8.17.0"
  },
  "ecs": {
    "version": "8.11.0"
  },
  "event": {
    "action": "added-member-to-group",
    "category": [
      "iam"
    ],
    "code": "4728",
    "kind": "event",
    "outcome": "success",
    "provider": "Microsoft-Windows-Security-Auditing",
    "sequence": 902240,
    "type": [
      "group",
      "change"
    ]
  },
  "group": {
    "domain": "CONTOSO",
    "id": "S-1-5-21-3457937927-2839227994-823803824-2601",
    "name": "Maintenance Operators"
  },
  "host": {
    "name": "dc01.contoso.local",
    "os": {
      "family": "windows",
      "type": "windows"
    }
  },
  "log": {
    "level": "information"
  },
  "related": {
    "user": [
      "olga.sokolova",
      "svc_maintenance_2"
    ]
  },
  "user": {
    "domain": "CONTOSO",
    "id": "S-1-5-21-3457937927-2839227994-823803824-1109",
    "name": "olga.sokolova",
    "target": {
      "domain": "CONTOSO",
      "group": {
        "domain": "CONTOSO",
        "id": "S-1-5-21-3457937927-2839227994-823803824-2601",
        "name": "Maintenance Operators"
      },
      "id": "S-1-5-21-3457937927-2839227994-823803824-2202",
      "name": "svc_maintenance_2"
    }
  },
  "winlog": {
    "channel": "Security",
    "computer_name": "dc01.contoso.local",
    "event_data": {
      "MemberName": "CN=svc_maintenance_2,CN=Users,DC=contoso,DC=local",
      "MemberSid": "S-1-5-21-3457937927-2839227994-823803824-2202",
      "SubjectDomainName": "CONTOSO",
      "SubjectLogonId": "0x91e545",
      "SubjectUserName": "olga.sokolova",
      "SubjectUserSid": "S-1-5-21-3457937927-2839227994-823803824-1109",
      "TargetDomainName": "CONTOSO",
      "TargetSid": "S-1-5-21-3457937927-2839227994-823803824-2601",
      "TargetUserName": "Maintenance Operators"
    },
    "event_id": "4728",
    "keywords": [
      "Audit Success"
    ],
    "level": "information",
    "logon": {
      "id": "0x91e545"
    },
    "opcode": "Info",
    "outcome": "success",
    "process": {
      "pid": 516,
      "thread": {
        "id": 1467
      }
    },
    "provider_guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}",
    "provider_name": "Microsoft-Windows-Security-Auditing",
    "record_id": "902240",
    "task": "Security Group Management",
    "time_created": "2026-09-01T07:02:05.777167+00:00",
    "version": 0
  }
}

Parameters

ParameterDefaultDescription
domainCONTOSONetBIOS domain
dns_domaincontoso.localDNS domain and Kerberos realm
domain_dnDC=contoso,DC=localDistinguished-name suffix
domain_sidS-1-5-21-3457937927-2839227994-823803824Domain SID prefix
dc_hostdc01.contoso.localController hostname
dc_agent_ida51465f9-72f4-4761-89bb-55de00ec6701Stable collector ID
dc_ephemeral_id943942bd-09ec-48aa-957d-2f12ecb83866Collector session ID
agent_version8.17.0Filebeat version
anomaly_modetrueEnable correlated episodes
anomaly_interval_hours24Episode interval in hours, from 6 to 8760

Related Generators