New Domain User Account Created
Detects the creation of a local user account in the Windows Security event logs. The rule filters out service accounts (those ending in '$') and events triggered by well-known system accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise. This helps identify unauthorized account creation, which can be an early indicator of persistence establishment or privilege escalation.
Microsoft Sentinel (KQL)

