Windows LSA event: Standard user SID in privileged AD groups (EventID 300)

Alerts when LSA Event 300 shows a standard user interacting with high-privileged group SIDs, excluding common domain admin patterns.

FreeReviewedSigma · Medium · v2
Product
windows
Service
lsa-server
Author
frack113 (SigmaHQ), DRL 1.1
Published
2023-01-13
Updated
2026-07-31

What it detects

This rule flags LSA operational events where a target account with a standard user SID prefix is associated with high-privilege group identifiers (local admin or various admin groups) within the SID list. Such events matter because attackers often gain privilege by adding themselves or compromised accounts to privileged groups, including local or domain-level administrators. The detection relies on Windows LSA-Server telemetry for EventID 300 and matches on TargetUserSid plus specific group-related SID values in SidList, excluding cases where TargetUserSid ends with specific domain/schema/enterprise admin patterns.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.