Detection rules › By eventMicrosoft-Windows-Security-Auditing event 47286 detection rules reference this event. View event page.Sigma (1)A Member Was Added to a Security-Enabled Global Group severity low T1098 Elastic (2)Active Directory Group Modification by SYSTEM T1098 User Added to Privileged Group in Active Directory T1098, T1098.007 Splunk (3)Windows AD add Self to Group T1098 Windows AD Privileged Group Modification T1098 Windows Increase in User Modification Activity T1098, T1562