Analytics
Low
✕
User added to the SMS Admins local group
A user was added to the SMS Admins local group. This may indicate a potential attack targeting the Microsoft Configuration Manager infrastructure.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)
Detector tags: Microsoft SCCM Analytics
Attacker's goals:
Gain administrative control over Microsoft Configuration Manager to facilitate lateral movement, deploy malicious payloads, or exfiltrate data.
Investigative actions:
Verify the activity with the performing user. Confirm that the group addition was not accidental. Review related logs (e.g., Active Directory, SCCM logs) to identify the source of the modification and associated accounts. Investigate the user's activity before and after the addition to determine if any unauthorized actions or privilege escalation attempts occurred.
- Test period:
- 3 Hours
- Deduplication:
- 1 Day
1 variation:
- User added to the SMS Admins group and removed Medium (parent: Low)