BlueKeep RDP Exploit: New Local Account Added to Admin/RDP Groups
Detects the creation of a new local user account followed by its immediate addition to the Administrators or Remote Desktop Users groups, a common pattern observed in post-exploitation activities related to CVE-2019-0708 (BlueKeep) for achieving persistent administrative access.
Sigma

