Non-Automation Service Principal Modifying Azure Runbooks

Detects modifications or publication of Azure Automation runbooks by users or service principals other than known, pre-approved automation service principals. This activity may indicate an unauthorized user or compromised service principal attempting to inject malicious code into automation workflows.