User Account Creation or Modification Activity

This rule detects the creation or modification of user accounts on Windows systems by monitoring Security Event IDs 4741 (A security-enabled local group was created) and 4742 (A computer account was changed). It summarizes the count of such changes per hour by the subject user name, which can help identify unusual or excessive account management activities.