Detection rules › By eventMicrosoft-Windows-Security-Auditing event 47325 detection rules reference this event. View event page.Sigma (1)User Added to Local Administrator Group severity medium T1078, T1098 Elastic (1)User Added to Privileged Group in Active Directory T1098, T1098.007 Splunk (3)Detect New Local Admin account T1136.001 Windows DnsAdmins New Member Added T1098 Windows Increase in User Modification Activity T1098, T1562