Techniques › T1098.007 › AN0865
AN0865 Analytic 0865
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects unauthorized additions of users or machine accounts to privileged local or domain groups (e.g., Administrators, Remote Desktop Users).</p>
- Detects
- T1098.007 Additional Local or Domain Groups
- Part of
- DET0310 Suspicious Addition to Local or Domain Groups
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Security | EventCode=4728, 4729, 4732, 4733, 4756, 4757 | DC0010 User Account Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
TargetGroup | Set to detect high-privileged groups like 'Administrators', 'Domain Admins', or 'Remote Desktop Users' |
TimeWindow | Restrict detections to business hours or approved maintenance windows |
UserContext | Filter out known automated processes or provisioning systems |