HuntCONSTRUCTED
Hunt: members added to Domain Admins and the other tier-zero groups
Every addition to a privileged Active Directory group in the last week, with who made it. Three event IDs, because the groups are three different scopes.
Privilege EscalationT1098.007checked 2026-09-26
Needs
- The Security log from every domain controller, with Audit Security Group Management enabled
Will also return
- Approved administrative changes. Compare against change tickets; the hunt is for the ones without one.
- Temporary elevation by privileged access tooling, which adds and removes members on a schedule.
Reading the results
Almost every row should match a change ticket. The rows that do not are the hunt. Pay particular attention to the ChangedBy column: an addition made by an account that is not a named administrator, or made from a workstation, is more interesting than the member that was added.
A hit without a ticket goes to the first-15-minutes checklist.
What it misses
Group membership granted through nesting (adding a group that is itself a member of Domain Admins) writes the event for the outer group only. Resolve nested membership separately, and include any group nested inside a tier-zero group in the list above.
KQL
Microsoft SentinelUntestedSecurityEvent
| where TimeGenerated > ago(7d)
| where EventID in (4728, 4732, 4756)
| where TargetUserName in~ ("Domain Admins", "Enterprise Admins", "Schema Admins", "Administrators",
"Account Operators", "Backup Operators", "DnsAdmins",
"Group Policy Creator Owners")
| project TimeGenerated, Computer, EventID, Group = TargetUserName, AddedMember = MemberName,
ChangedBy = SubjectUserName, ChangedByDomain = SubjectDomainName
| order by TimeGenerated descSPL
Splunk with the Add-on for Microsoft WindowsUntestedindex=wineventlog sourcetype="WinEventLog:Security" (EventCode=4728 OR EventCode=4732 OR EventCode=4756) earliest=-7d
| search Group_Name IN ("Domain Admins", "Enterprise Admins", "Schema Admins", "Administrators", "Account Operators", "Backup Operators", "DnsAdmins", "Group Policy Creator Owners")
| table _time host EventCode Group_Name Member_Name Subject_Account_Name
| sort - _timeElastic
EQL, Winlogbeat security module or Elastic AgentUntestediam where event.code in ("4728", "4732", "4756") and
group.name in~ ("Domain Admins", "Enterprise Admins", "Schema Admins", "Administrators",
"Account Operators", "Backup Operators", "DnsAdmins",
"Group Policy Creator Owners")