You can ensure that administrative and service accounts are used appropriately and to detect any unauthorized or risky activity.
Use the Privilegelevel search filter to narrow your search to specific administrative groups:
Domain Admin: Shows logons by members of highly privileged Active Directory groups.
Local Admin: Shows logons by members of the local administrators group on an endpoint.
Alternatively, use the Domain group membership search to look for activity from custom administrative groups specific to your organization (for example, Tier 1 Support).
Review the activity for these accounts. Look for logons to standard user workstations or systems that the administrator has no business accessing.
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat hunting with advanced detection modules > Detection using Logon Tracker
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.4.x - Windows Product Guide > Using the software > Using monitoring rules
Application Control and Change Control > Application and Change Control 8.x > Trellix Application and Change Control 8.3.x - Windows Product Guide > Using the software > Using monitoring rules