Analytics Informational

User added to a group and removed

A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:

Elevate permissions and establish persistence.

Investigative actions:

Verify the activity with the performing user. Confirm that the group addition was not accidental. Check for any suspicious actions performed by the added user. Check for a possible compromise of the initiating user.

Test period:
10 Hours
Deduplication:
1 Day
2 variations:
  • Rare privileged group addition and removal Medium (parent: Informational)
  • User added to a privileged group and removed Low (parent: Informational)