Non-Automation Service Principal Modifying Azure Runbooks
Detects modifications or publication of Azure Automation runbooks by users or service principals other than known, pre-approved automation service principals. This activity may indicate an unauthorized user or compromised service principal attempting to inject malicious code into automation workflows.
Microsoft Sentinel (KQL)

