Skip to main content

Privilege Creep/Escalation

The Privilege Creep/Escalation option uses the Account Name field to determine which user is targeted when searching for threats. You can use wildcard characters (%).

The Privilege Creep/Escalation option contains the following cards:

privilegecreep

  • Last Twenty Successful Group Modification Events (Member) – Shows the details of the last twenty successful group modification events where the Account Name matches the Affected Object, as recorded in the specified timeframe
  • Last Twenty Successful Group Modification Events (Perpetrator) – Shows the details of the last twenty successful group modification events where the Account Name matches the Perpetrator, as recorded in the specified timeframe

The specified timeframe defaults to All Time.