Powershell LocalAccount Manipulation — Detection Rule

Adversaries may manipulate accounts to maintain access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups

Read the full analysis on IntelFusions