Windows EventInformation
Windows Event ID 4764 – Microsoft-Windows-Security-Auditing: Group Member Added
Event ID 4764 logs when a user account is added to a security-enabled group in Active Directory or local system, providing audit trail for group membership changes.