Changes made to a group, such as membership, name, or permissions (ex: Windows EID 4728 or 4732, AWS IAM UpdateGroup). Examples:
Set-AzureADGroup -ObjectId <GroupId> -DisplayName "New Name"aws iam update-group --group-name <GroupName> --new-path "/admin/"PATCH https://admin.googleapis.com/admin/directory/v1/groups/<groupKey>PATCH https://graph.microsoft.com/v1.0/groups/<groupId>Data Collection Measures:
UpdateGroup, AttachGroupPolicy, RemoveUserFromGroup.| Name | Channel |
|---|---|
| m365:unified | Add member to group |
| ID | Name | Technique Detected |
|---|---|---|
| DET0319 | Detection Strategy for T1136.003 - Cloud Account Creation across IaaS, IdP, SaaS, Office | T1136.003 |