New Local/Domain Admin Account Created Then Used Within Minutes (Ransomware Staging)
This rule detects scenarios where a new user account is created (Event ID 4720) and is subsequently logged into (Event ID 4624) within a 30-minute window. This behavior can indicate an adversary creating a backdoor or service account for persistence or lateral movement, followed by immediate usage of that account.
Microsoft Sentinel (KQL)

