User Added to Local Administrators Group (ad720b90-25ad-43ff-9b5e-5c841facc8e5)
Detects addition of users to the local administrator group via "Net" or "Add-LocalGroupMember".
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Account Manipulation - T1098 (a10641f4-87b4-45a3-a906-92a149cb2c27) | Attack Pattern | User Added to Local Administrators Group (ad720b90-25ad-43ff-9b5e-5c841facc8e5) | Sigma-Rules | 1 |