User account added to built in domain local or global group

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies when a user account has been added to a privileged built in domain local group or global group such as the Enterprise Admins, Cert Publishers or DnsAdmins. Be sure to verify this is an expected addition.

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID a35f2c18-1b97-458f-ad26-e033af18eb99
Severity Low
Kind Scheduled
Tactics Persistence, PrivilegeEscalation
Techniques T1098, T1078
Required Connectors SecurityEvents, WindowsSecurityEvents, WindowsForwardedEvents
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules