Azure Serverless Execution - Function App Creation Followed by External IP Trigger

This rule monitors the creation of new Azure Function Apps and identifies those that receive external, non-private network requests within 48 hours of their creation. This pattern may indicate the deployment of malicious or unauthorized serverless infrastructure for command-and-control, proxying, or automated tasks.