Azure Serverless Execution - Function App Creation Followed by External IP Trigger
This rule monitors the creation of new Azure Function Apps and identifies those that receive external, non-private network requests within 48 hours of their creation. This pattern may indicate the deployment of malicious or unauthorized serverless infrastructure for command-and-control, proxying, or automated tasks.
Microsoft Sentinel (KQL)

