Anomalous Logon (4624) Followed by DC Computer Account Change (4742)

Detects an authentication event followed by a computer account change event (Event ID 4742) targeting a domain controller computer account. This pattern may indicate unauthorized modifications to domain controller machine accounts, which is often associated with persistence or privilege escalation attempts.