ChecklistCONSTRUCTEDUntestedMembers

First 15 minutes: an account was added to Domain Admins

A tier-zero group changed and nobody has a ticket for it. Whoever made the change is at least as compromised as the account they added. How to confirm, contain and scope without handing the operator another credential.

critical severityPrivilege EscalationT1098.007T1078.002T1003.006

The clock starts when

Event 4728, 4732 or 4756 shows an account added to Domain Admins, Enterprise Admins, Administrators or another tier-zero group, and there is no approved change for it.

  1. minutes 0 to 5Confirm the change and keep the record3 lines, 1 where evidence expires
  2. minutes 5 to 10Contain without spreading credentials3 lines
  3. minutes 10 to 15Assume the domain is in play4 lines

sources

  1. MITRE ATT&CK T1098.007, Account Manipulation: Additional Local or Domain Groups · primary
  2. Microsoft Learn: Appendix L, Events to Monitor
  3. Microsoft Learn: 4732, A member was added to a security-enabled local group
  4. Microsoft Learn: best practices for securing Active Directory

Tags: first-15 · active-directory · privilege-escalation · domain-admins · tier-zero · windows · T1098.007