New WordPress administrator account created shortly after anomalous login/upload event
This rule detects the creation of a new WordPress administrator account within a short window (15 minutes) of an anomalous authentication or registration event on the same account or session. It is designed to identify post-exploitation activity, specifically persistence mechanisms following the exploitation of web application vulnerabilities like arbitrary file uploads or authentication bypasses in WordPress plugins.
Microsoft Sentinel (KQL)

