Azure Key Vault Secret/Key/Certificate Enumeration Spike by Single Identity

Detects anomalous credential access behavior in Azure Key Vault where a single identity performs more than 20 secret, key, or certificate read/list operations within a 5-minute window. This behavior is indicative of potential unauthorized reconnaissance or exfiltration of secrets stored in Key Vaults, excluding known automation service principals.