Windows User Group Membership Modified - Privilege Escalation or Persistence

Detects when a user account is added to a security-enabled global, local, or universal group in Active Directory. This behavior is captured by monitoring Security Events 4728 (global group), 4732 (local group), and 4756 (universal group). The rule flags actions performed by user accounts (excluding system accounts) and aggregates them by the source account performing the modification.