Serverless Execution - Suspicious Azure Function Deployment

This rule detects potentially malicious modification or configuration changes to Azure Function Apps. It monitors for operations such as creation, updates, and configuration changes that contain suspicious indicators like hardcoded credentials (TOKEN, SECRET, PASS), potential reverse shell patterns, or large Base64 encoded payloads. The rule specifically excludes known CI/CD pipeline callers to minimize false positives.