Detection rules › By eventMicrosoft-Windows-Security-Auditing event 46271 detection rule reference this event. View event page.Splunk (1)Windows Domain Admin Impersonation Indicator T1558