HuntCONSTRUCTED

Hunt: members added to Domain Admins and the other tier-zero groups

Every addition to a privileged Active Directory group in the last week, with who made it. Three event IDs, because the groups are three different scopes.

Privilege EscalationT1098.007checked 2026-09-26

Needs

  • The Security log from every domain controller, with Audit Security Group Management enabled

Will also return

  • Approved administrative changes. Compare against change tickets; the hunt is for the ones without one.
  • Temporary elevation by privileged access tooling, which adds and removes members on a schedule.

Reading the results

Almost every row should match a change ticket. The rows that do not are the hunt. Pay particular attention to the ChangedBy column: an addition made by an account that is not a named administrator, or made from a workstation, is more interesting than the member that was added.

A hit without a ticket goes to the first-15-minutes checklist.

What it misses

Group membership granted through nesting (adding a group that is itself a member of Domain Admins) writes the event for the outer group only. Resolve nested membership separately, and include any group nested inside a tier-zero group in the list above.

KQL

Microsoft SentinelUntestedwindow: 7 days, set in the query

4728 is a global group (Domain Admins), 4732 a domain local group (Administrators), 4756 a universal group (Enterprise Admins, Schema Admins).

SecurityEvent
| where TimeGenerated > ago(7d)
| where EventID in (4728, 4732, 4756)
| where TargetUserName in~ ("Domain Admins", "Enterprise Admins", "Schema Admins", "Administrators",
                           "Account Operators", "Backup Operators", "DnsAdmins",
                           "Group Policy Creator Owners")
| project TimeGenerated, Computer, EventID, Group = TargetUserName, AddedMember = MemberName,
          ChangedBy = SubjectUserName, ChangedByDomain = SubjectDomainName
| order by TimeGenerated desc

SPL

Splunk with the Add-on for Microsoft WindowsUntestedwindow: 7 days, set with earliest

Field names for the group and member differ between classic and XML rendering. Check one 4728 event and adjust Group_Name and Member_Name if needed.

index=wineventlog sourcetype="WinEventLog:Security" (EventCode=4728 OR EventCode=4732 OR EventCode=4756) earliest=-7d
| search Group_Name IN ("Domain Admins", "Enterprise Admins", "Schema Admins", "Administrators", "Account Operators", "Backup Operators", "DnsAdmins", "Group Policy Creator Owners")
| table _time host EventCode Group_Name Member_Name Subject_Account_Name
| sort - _time

Elastic

EQL, Winlogbeat security module or Elastic AgentUntestedwindow: 7 days, set in the time picker
iam where event.code in ("4728", "4732", "4756") and
  group.name in~ ("Domain Admins", "Enterprise Admins", "Schema Admins", "Administrators",
                  "Account Operators", "Backup Operators", "DnsAdmins",
                  "Group Policy Creator Owners")

sources

  1. Microsoft Learn: Appendix L, Events to Monitor · primary
  2. Microsoft Learn: SecurityEvent table reference
  3. MITRE ATT&CK T1098.007, Account Manipulation: Additional Local or Domain Groups

Tags: hunting · active-directory · domain-admins · privilege-escalation · windows · sentinel · splunk · elastic · T1098.007