Analytics
Informational
✕
User added to a group and removed
A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Attacker's goals:
Elevate permissions and establish persistence.
Investigative actions:
Verify the activity with the performing user. Confirm that the group addition was not accidental. Check for any suspicious actions performed by the added user. Check for a possible compromise of the initiating user.
- Test period:
- 10 Hours
- Deduplication:
- 1 Day
2 variations:
- Rare privileged group addition and removal Medium (parent: Informational)
- User added to a privileged group and removed Low (parent: Informational)