Hidden Admin Account Creation with RDP and WDigest Registry Enablement

Detects the creation of a local administrative account with a hidden naming convention (ending in $) accompanied by a cluster of registry modifications designed to obscure the account from the logon screen, enable WDigest plaintext credential caching, relax RDP authentication requirements (disable NLA, enable RDP), and disable UAC remote restrictions. This activity is highly indicative of post-exploitation persistence and credential harvesting configurations following initial access via SQL server exploitation.