Added Credentials to Existing Application
Description
Detects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials.
Query · sigma
selection: properties.message: - Update application – Certificates and secrets management - Update Service principal/Update Application condition: selection
Known false positives
- When credentials are added/removed as part of the normal working hours/workflows