AdminCount Attribute Modification Detection

This rule detects modifications to the 'AdminCount' attribute in Active Directory, indicated by Event ID 5136. Changes to this attribute can signify privilege escalation attempts or modifications to highly privileged accounts.