Group Change
Enabled by default
Service: Microsoft Windows Security auditing
Log type: Security
Group change can indicate unauthorized privilege escalation of a whole user group. This should be monitored so that user permissions are known and not over reaching. This log is recommended by the NSA Cyber Event Forwarding Guidance.
Get-WinEvent -FilterHashTable @{LogName='Security';ID='4735'} -MaxEvents 1 | Format-List
auditpol /get /subcategory:"security group management"
auditpol /set /subcategory:"security group management" /Success:Disable /Failure:Disable
auditpol /set /subcategory:"security group management" /Success:Enable /Failure:Enable
Compliance
NSA Event Forwarding
Level: Recommended
https://github.com/nsacyber/Event-Forwarding-Guidance/tree/master/Events
Changes made to a security group are automatically logged and can be viewed in the security tab of the Event Viewer. To view these logs, sort or filter by event ID 4735.
data:image/s3,"s3://crabby-images/9eab2/9eab25bad5b0798f39243986aa0ebeb9a72ba2f5" alt=""
To view this log in the command line with Get-WinEvent, open PowerShell as an administrator. From here, enter the command Get-WinEvent -FilterHashTable @{LogName='Security';ID='4735'} -MaxEvents 1 | Format-List
data:image/s3,"s3://crabby-images/e1b22/e1b22b42abcfa91a6f66f56cfd4af6a6d292481c" alt=""
To view this log in the command line with wevtutil, open PowerShell or Command Prompt as an administrator. From here, enter the commandwevtutil qe Security "/q:*[System [(EventID=4735)]]"
data:image/s3,"s3://crabby-images/be440/be440ba675f111ec8467d016710f37dc995054c1" alt=""