Local Backdoor Account Creation with Hardcoded Password 'Numlock!123'
This rule monitors for the execution of 'net.exe' or 'net1.exe' with command line arguments containing 'user', '/add', and a specific suspicious string 'Numlock!123'. This pattern is indicative of an adversary attempting to create a local user account on a Windows system using a hardcoded or known adversary credential.
CQL

