Analytics BIOC
Informational
✕
A user was added to a Windows security group
A user was added to a Windows security group.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:
Privilege escalation using a valid account.
Investigative actions:
Check the user who added the account to the group and verify its activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- User added a member to a Windows privileged group for the first time Medium (parent: Informational)
- User added to a Windows privileged group Low (parent: Informational)
- User removed from a Windows privileged group Informational
- A user was removed from a Windows security group Informational