CTD-000146

AD user added to privileged group

High
Active Directory
Credential Access Privilege Escalation
v54

Signature Identity

CTD-000146
Threat ID
54
Version
IOA-IOC
Indicator Type

Threat Description

Modification of privileged group membership might be an indication of a privilege escalation attempt by a threat actor. This activity could signal unauthorized access or an attempt to gain elevated permissions within the system.

Users can configure alerts based on AdminCount or sAMAccountName to monitor and detect suspicious changes to privileged group memberships. However, the built-in privileged groups will always trigger an alert, regardless of user configuration, ensuring that critical security events are not overlooked.

NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as groups with adminCount=1 and a well-known SID.

NOTE: This threat rule includes a built-in lookback parameter set to 48 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Restore Configuration

Remediation

  1. Review the changes in privileged group membership.
  2. Use rollback in Change History to undo unwanted modifications.

Frequently Asked Questions

What does AD user added to privileged group mean?

An Active Directory user has been added as a member of a group with adminCount=1 and a well-known SID, which is considered a privileged group. This modification indicates that the user's privileges have been elevated.

This activity enables attackers to escalate privileges and access sensitive data within the system, directly granting them unauthorized access or elevated permissions. The attacker gains the capability to perform malicious operations by exploiting the elevated permissions.

Attackers can use the added user's credentials to gain access to sensitive data or systems within the organization, and perform malicious operations by escalating privileges. The attacker gains the capability to persist in the system and evade detection.

Cayosoft Guardian continuously monitors changes in privileged group membership, identifying any additions of users with adminCount=1 and a well-known SID. This ensures that critical security events are not overlooked.

Cayosoft Guardian alerts administrators when changes in privileged group membership occur, enabling them to review and correct these changes. Ongoing monitoring also allows teams to quickly detect any re-additions or modifications that might indicate a privilege escalation attempt.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Privileged Access Management
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Restore Configuration
Indicator Types
IOA IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical