Unauthorized Domain Admin Account Creation
Detects the creation of new members in the 'Domain Admins' or 'Enterprise Admins' groups by monitoring Windows Security Event ID 4728. This event indicates that a member was added to a security-enabled global group. The rule specifically looks for additions to highly privileged administrative groups, which could indicate unauthorized privilege escalation or persistence.
Microsoft Sentinel (KQL)

