Potential Persistence Through New Device Registration

Detects newly registered devices following account compromise. Threat actors frequently register rogue devices after obtaining tokens to maintain persistence.

Microsoft Sentinel (KQL)