Active Directory Object Unexpectedly Deleted
Detects the deletion of directory service objects such as users, groups, organizational units, computers, or trusted domains. This is identified via Windows Security Event ID 5141, which tracks when a directory object is deleted.
Microsoft Sentinel (KQL)

