Detection rules › By eventMicrosoft-Windows-Security-Auditing event 47413 detection rules reference this event. View event page.Sigma (1)Add or Remove Computer from DC severity low T1207 Splunk (2)Windows Computer Account Created by Computer Account T1558 Windows Computer Account With SPN T1558