Windows Security: Changes to "ESX Admins" Domain Group Membership

Alerts on domain group management events involving the "ESX Admins" group name, which may grant privileged access.

FreeReviewedSigma · High · v5
Product
windows
Service
security
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-07-30
Updated
2026-07-31

What it detects

This rule alerts on Windows Security events indicating creation, modification, or membership changes involving a domain group named "ESX Admins". Such group changes can grant or expand elevated administrative access in environments where this group name confers privileged permissions, making it a valuable signal for potential exploitation or abuse. It relies on Windows Security audit events 4727, 4728, 4731, 4737, 4754, 4755, and 4756 combined with the presence of the exact group name keyword "ESX Admins".

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.