Name:O365 Service Principal New Client Credentials id:a1b229e9-d962-4222-8c62-905a8a010453 version:13 date:None author:Mauricio Velazco, Splunk status:production type:TTP Description:The following analytic detects the addition of new credentials for Service Principals within an Office 365 tenant. It uses O365 audit logs, focusing on events related to credential modifications or additions in the AzureActiveDirectory workload. This activity is significant because Service Principals represent application identities, and their credentials allow applications to authenticate and access resources. If an attacker successfully adds or modifies these credentials, they can impersonate the application, leading to unauthorized data access, data exfiltration, or malicious operations under the application's identity. Data_source:
-O365
search:`o365_management_activity` Workload=AzureActiveDirectory Operation="Update application*Certificates and secrets management "
| fillnull
| stats earliest(_time) as firstTime latest(_time) as lastTime BY user ModifiedProperties{}.NewValue object ObjectId dest signature src vendor_account vendor_product