The use case for this test is Privilege Escalation—Add a user to the Domain Admins Group.
Privilege Escalation is a common way for an attacker to gain unauthorized asses to a system/account. In many cases that first point of attack will not grant attackers with the level of access they need. They will then attempt privilege escalation to gain more permissions or obtain access to additional, more sensitive systems.
How to Test
Testing is only for clients which WMI logs are being monitored. This activity can only be done by a Local Admin or a Domain Admin. There are usually very few admin users chosen within an organization, so these actions should be closely monitored for any unauthorized activity.
Open Start > Computer Management > Local Users and Groups.
Click on Users, right-click on the user and click Properties.
On the Member Of tab, click Add.
Click Advanced, then Find Now.
Look for Domain Admins in the search results. Click OK.
This adds the user to the Domain Admins group. Click OK.
Click Advanced, then Find Now.
Look for Domain Admins in the search results. Click OK.