Entra ID App Credential Added by Non-Owner (T1098.001)
This rule detects the addition of new certificates or client secrets to Azure App Registrations or Service Principals by a user who is not recorded as an owner of that application in the last 90 days. This behavior is a common persistence and privilege escalation technique used by attackers to maintain access to cloud environments.
Microsoft Sentinel (KQL)

