On one of my Domain Controllers at about 9.30pm every night I am seeing numerous 4724 events in the security Log. from the event details I cannot tell what is trying to change these passwords?
An attempt was made to change an account's password.
Subject:
Security ID: SYSTEM
Account Name: ServerName$
Account Domain: EXAMPLE
Logon ID: 0x275ad6d4
Target Account:
Security ID: EXAMPLE\wanderson
Account Name: wanderson
Account Domain: EXAMPLE
Additional Information:
Privileges -