BeyondTrust User Removed from Administrators Group

Detects configuration events in BeyondTrust Password Safe where a user is removed from a group containing 'Administrators' in its name. This monitors for potential unauthorized removal of administrative privileges or interference with operational access.