User Added to Local Administrator Group — Detection Rule

Detects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity

Read the full analysis on IntelFusions