User added to a group and removed
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Hours
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation (T1098), Valid Accounts (T1078)
Severity
Informational
Description
A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise.
Attacker's Goals
Elevate permissions and establish persistence.
Investigative actions
Verify the activity with the performing user.
Confirm that the group addition was not accidental.
Check for any suspicious actions performed by the added user.
Check for a possible compromise of the initiating user.
Variations
Was this helpful?
