AdminCount Attribute Modification Detection
This rule detects modifications to the 'AdminCount' attribute in Active Directory, indicated by Event ID 5136. Changes to this attribute can signify privilege escalation attempts or modifications to highly privileged accounts.
Microsoft Sentinel (KQL)

