Unauthorized Domain Account Creation - Active Directory Persistence
This rule detects the creation of a new domain user account followed by its immediate addition to a privileged Active Directory group within a short timeframe. It specifically ignores common provisioning accounts and service accounts. A high risk score is assigned if the privileged group assignment occurs within 5 minutes of account creation, flagging potentially malicious account takeovers or privilege escalation activity.
Microsoft Sentinel (KQL)

