Detect New Local Admin Account
This search looks for newly created accounts that have been elevated to local administrators.
Detect New Local Admin Account Help
You must be ingesting Windows event logs using the Splunk Windows TA and collecting event code 4720 and 4732
Open in Search