Skip to content

[BUG] Detect New Local Admin Account #3730

@jwindley

Description

@jwindley

With WindowsXML logs, the group name in a 4732 event seems to be in the field "TargetSid" rather than Group_Name. In the logs I'm looking at, the value also is "BUILTIN\Administrators" as well, rather than "Administrators". Can someone from Security content team please check?
Windows Add-on 9.0.1
ESCU 5.16.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions