Local backdoor account creation with hardcoded password Numlock!123

Detects the execution of the 'net user' command with the '/add' parameter using the hardcoded password 'Numlock!123'. This pattern is frequently observed as a persistence mechanism employed by threat actors during ransomware operations to establish unauthorized administrative access.