Akira RDP Lateral Movement - net.exe Domain Admin Manipulation via PowerShell
This rule detects a remote interactive logon (Logon Type 10) via RDP, followed by a PowerShell process executing 'net.exe' with sensitive administrative arguments such as 'administrator', '/active:yes', or '/dom'. This pattern is highly indicative of an adversary attempting to elevate privileges or modify domain/local account properties after establishing initial access via Remote Desktop.
Cortex XDR

