New Domain User Account Created

Detects the creation of a local user account in the Windows Security event logs. The rule filters out service accounts (those ending in '$') and events triggered by well-known system accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise. This helps identify unauthorized account creation, which can be an early indicator of persistence establishment or privilege escalation.