This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
User Added To Highly Privileged Group
Original Source:
[Sigma source]
Title:
User Added To Highly Privileged Group
Status:
test
Description:
Detects addition of users to highly privileged groups via "Net" or "Add-LocalGroupMember".
References:
-https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2024-02-23
modified:
None
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1098'
Logsource:
category: process_creation
product: windows
Detection:
selection_main:
- CommandLine|contains|all
:
- 'localgroup '
- ' /add'
- CommandLine|contains|all
:
- 'Add-LocalGroupMember '
- ' -Group '
selection_group:
CommandLine|contains
:
-'Group Policy Creator Owners'
-'Schema Admins'
condition
:
all of selection_*
Falsepositives:
-Administrative activity that must be investigated
Level:
high