Rogue Domain Admin Account Creation via net.exe (Bumblebee/AdaptixC2/Akira)

Detects the creation of a new domain user followed by its addition to sensitive, high-privileged groups (e.g., Domain Admins, Enterprise Admins) using the native Windows net.exe or net1.exe utilities. This pattern aligns with known post-compromise activity observed in campaigns like Bumblebee, AdaptixC2, and Akira ransomware, where attackers create stealthy, elevated accounts (e.g., masquerading as backup service accounts) to maintain persistence and full domain control.