Detection rules › Sigma
A Member Was Removed From a Security-Enabled Global Group
Detects activity when a member is removed from a security-enabled global group
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Persistence | T1098 Account Manipulation |
| Privilege Escalation | T1098 Account Manipulation |
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| Security-Auditing | 633 | |
| Security-Auditing | 4729 | A member was removed from a security-enabled global group. |