Analytics BIOC
Medium
✕
Machine account was added to a domain admins group
A machine account was added to a domain admins group.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
Attacker's goals:
Privilege escalation using a valid account.
Investigative actions:
Check the user who added the account to the group and verify its activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day