Analytics BIOC
Informational
✕
Member added to a Windows local security group
A member was added to a Windows local security group.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:
Privilege escalation using a valid account.
Investigative actions:
Check the user who added the account to the group and verify its activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- User added to the Windows local Administrator group Low (parent: Informational)
- Member added to the Windows local Administrator group Informational