SID History Injection - Potential Privilege Escalation via SID-History Attribute

This rule detects the modification of the SID History attribute on Active Directory accounts (Event ID 4765) or failed attempts to do so (Event ID 4766). The SID History attribute can be abused to gain unauthorized access and escalate privileges across domain boundaries by injecting well-known or administrative SIDs, a technique known as SID-History Injection.