Service Principal Credential Added Outside Change Window
This rule detects when new credentials (secrets or certificates) are added to an Azure Active Directory Service Principal. It flags this activity as suspicious if it occurs outside of typical business hours or if it exhibits signs of 'rapid re-keying', where multiple credentials are added to the same service principal within a 24-hour window. This behavior is a common indicator of persistence maintenance or credential rotation to support unauthorized access.
Splunk (SPL)

