Get-ADObject -Identity <ObjectIdentity> | Get-QADObjectSecurity -Owner

 

 

or

 

query your DCs for event id 624:

$filter = “LogFile=’Security’ AND EventCode=624 AND SourceName=’security’ AND CategoryString=’Account Management’ AND Message LIKE ‘%User Account Created%’ AND Type=’Audit Success'”
Get-WmiObject -Class Win32_NTLogEvent -Filter $filter -cn DC1,DC2 | Select-Object @{n=’UserName';e={$_.InsertionStrings[0]}},@{n=’Creator';e={$_.InsertionStrings[3]}}