Mass Cloud Control-Plane Enumeration by Agent Identity

Detects anomalous, high-volume enumeration activity (List/Get/Read operations) performed by a single identity across multiple Azure resource providers within a short time window, indicative of automated reconnaissance by a compromised service principal or managed identity.