Dikshant Lather · Sep 25, 2026 Uncovering Local Windows Account Creation via Command Line with KQL Spot unauthorized backdoor user accounts created on endpoints via net.exe, net1.exe, and PowerShell local user management cmdlets. Threat Hunting 2 min read 0 0