LSA Restricted Admin Registry Modification
Detects registry changes affecting DisableRestrictedAdmin, specifically when it is set to '00000000' (disabled). This modification could weaken authentication protections or facilitate credential theft techniques by allowing the use of cached credentials for remote connections.
Microsoft Sentinel (KQL)

