Runas.exe /savecred or /netonly Credential Abuse (T1134.001)

Detects the execution of 'runas.exe' with the '/savecred' or '/netonly' parameters. The '/savecred' parameter allows the use of credentials previously stored in the credential manager, while '/netonly' allows the use of credentials for remote network resources without authenticating locally. Both flags can be abused by adversaries to persist or move laterally with compromised or cached credentials while evading local authentication monitoring. The rule excludes common system-signed processes originating from the Windows System32 directory.