Rogue WordPress Admin Creation (OptinMonster Campaign)
Identifies HTTP POST requests indicative of rogue administrator account creation patterns ('dev_xxxxxx' or 'developer_api1') used in the OptinMonster, TrustPulse, and PushEngage supply chain attack. This rule specifically looks for POST requests to WordPress user creation endpoints containing attacker-controlled account names in the URI query.
Microsoft Sentinel (KQL)

