Detection rules › Kusto Query Language

User account added to built in domain local or global group

Author
Microsoft Security Research
Source
upstream

'Identifies when a user account has been added to a privileged built in domain local group or global group such as the Enterprise Admins, Cert Publishers or DnsAdmins. Be sure to verify this is an expected addition.'

MITRE ATT&CK coverage

TacticTechniques
Initial AccessT1078 Valid Accounts
PersistenceT1078 Valid Accounts, T1098 Account Manipulation
Privilege EscalationT1078 Valid Accounts, T1098 Account Manipulation
Defense EvasionT1078 Valid Accounts

Event coverage

ProviderEvent IDTitle
Security-Auditing4728A member was added to a security-enabled global group.
Security-Auditing4732A member was added to a security-enabled local group.
Security-Auditing4756A member was added to a security-enabled universal group.

Stages and Predicates

Stage 1: source

<union>

Stage 2: union

union of 2 branches

Stage 3: extend

Stage 4: extend

Stage 5: extend

Stage 6: project-away