Remove Account From Domain Admin Group
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "PowerShell Script Block Logged" AND SCRIPTEXECUTED contains "Remove-ADGroupMember" AND SCRIPTEXECUTED contains "-Identity " AND SCRIPTEXECUTED contains "-Members " select Action1.HOSTNAME,Action1.MESSAGE,Action1.SCRIPTEXECUTED
Detection
Execution Mode
realtime
Log Sources
Active Directory
Author
frack113


