Rogue Domain Admin Account Creation via net.exe (Bumblebee/AdaptixC2/Akira)
Detects the creation of a new domain user followed by its addition to sensitive, high-privileged groups (e.g., Domain Admins, Enterprise Admins) using the native Windows net.exe or net1.exe utilities. This pattern aligns with known post-compromise activity observed in campaigns like Bumblebee, AdaptixC2, and Akira ransomware, where attackers create stealthy, elevated accounts (e.g., masquerading as backup service accounts) to maintain persistence and full domain control.
Sigma

