Added Credentials to Existing Application

 Original Source: [Sigma source]
Title: Added Credentials to Existing Application
Status: test
Description:Detects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials.
References:
  -https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-credentials
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'
Date: 2022-05-26
modified:2026-08-20
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1098.001'
  • -'attack.persistence'
Logsource:
  • product: azure
  • service: auditlogs
Detection:
  selection:
    properties.message:
      -'Update application - Certificates and secrets management'
      -'Update Service principal/Update Application'

  condition:selection
Falsepositives:
  -When credentials are added/removed as part of the normal working hours/workflows
Level: high