Title:Added Credentials to Existing Application Status:test Description:Detects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials. References: -https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-credentials Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' Date: 2022-05-26 modified:2026-08-20 Tags:
-'attack.privilege-escalation'
-'attack.t1098.001'
-'attack.persistence'
Logsource:
product: azure
service: auditlogs
Detection: selection: properties.message: -'Update application - Certificates and secrets management' -'Update Service principal/Update Application'
condition:selection Falsepositives:
-When credentials are added/removed as part of the normal working hours/workflows Level:high