Detection rules › Kusto Query Language

New user created and added to the built-in administrators group

Author
Microsoft Security Research
Source
upstream

'Identifies when a user account was created and then added to the builtin Administrators group in the same day. This should be monitored closely and all additions reviewed.'

MITRE ATT&CK coverage

TacticTechniques
Initial AccessT1078 Valid Accounts
PersistenceT1078 Valid Accounts, T1098 Account Manipulation
Privilege EscalationT1078 Valid Accounts, T1098 Account Manipulation
Defense EvasionT1078 Valid Accounts

Event coverage

ProviderEvent IDTitle
Security-Auditing4720A user account was created.
Security-Auditing4732A member was added to a security-enabled local group.

Stages and Predicates

Stage 1: source

<union>

Stage 2: union

union of 2 branches

Stage 3: join

Stage 4: project

Stage 5: extend

Stage 6: extend

Stage 7: project-away