Account Added to Privileged Active Directory Group

This rule monitors for additions of users to highly sensitive Active Directory groups, such as Domain Admins or Enterprise Admins, by tracking specific Windows security events (4728, 4732, 4756). Unauthorized membership changes in these groups are a classic indicator of privilege escalation or persistence maintenance by an adversary.