Windows AD User Added to Monitored Group
Detects Windows Security events (Event IDs 4728 and 4756) where a member is added to a sensitive or privileged Active Directory domain global or universal security group. The rule compares the target group against a locally maintained inventory of monitored groups to identify potential unauthorized privilege escalation or persistence.
Cortex XDR

