BeyondTrust User Added to Administrators Group

Detects configuration events in BeyondTrust Password Safe where a user is added to a group containing 'Administrators' in its name. This behavior can indicate unauthorized privilege escalation or persistence within the BeyondInsight/Password Safe environment.