kevmap

TechniquesT1098.007 › AN0865

AN0865 Analytic 0865

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects unauthorized additions of users or machine accounts to privileged local or domain groups (e.g., Administrators, Remote Desktop Users).</p>
Detects
T1098.007 Additional Local or Domain Groups
Part of
DET0310 Suspicious Addition to Local or Domain Groups

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4728, 4729, 4732, 4733, 4756, 4757DC0010 User Account Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TargetGroupSet to detect high-privileged groups like 'Administrators', 'Domain Admins', or 'Remote Desktop Users'
TimeWindowRestrict detections to business hours or approved maintenance windows
UserContextFilter out known automated processes or provisioning systems