User Added To Highly Privileged Group

 Original Source: [Sigma source]
Title: User Added To Highly Privileged Group
Status: test
Description:Detects addition of users to highly privileged groups via "Net" or "Add-LocalGroupMember".
References:
  -https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2024-02-23
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1098'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_main:
    - CommandLine|contains|all:
      - 'localgroup '
      - ' /add'
    - CommandLine|contains|all:
      - 'Add-LocalGroupMember '
      - ' -Group '
  selection_group:
    CommandLine|contains:
      -'Group Policy Creator Owners'
      -'Schema Admins'

  condition:all of selection_*
Falsepositives:
  -Administrative activity that must be investigated
Level: high