This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
User Added to Local Administrator Group
Original Source:
[Sigma source]
Title:
User Added to Local Administrator Group
Status:
stable
Description:
Detects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity
References:
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4732
-https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers
Author:
Florian Roth (Nextron Systems)
Date:
2017-03-14
modified:
2021-01-17
Tags:
-'attack.initial-access'
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1078'
-'attack.persistence'
-'attack.t1098'
Logsource:
product: windows
service: security
Detection:
selection_eid:
EventID
:
'4732'
selection_group:
TargetUserName|startswith
:
'Administr'
TargetSid
:
'S-1-5-32-544'
filter_main_computer_accounts:
SubjectUserName|endswith
:
'$'
condition
:
all of selection_* and not 1 of filter_*
Falsepositives:
-Legitimate administrative activity
Level:
medium