Suspicious Azure Automation Runbook Execution - Credential Theft or Code Exec
This rule detects potentially malicious activity within Azure Automation by monitoring for the creation or modification of runbooks and jobs, combined with the presence of suspicious command-line or script patterns in job stream output, such as credential harvesting (e.g., Get-AutomationPSCredential) or execution of web-based payloads (e.g., IEX, Invoke-WebRequest).
Microsoft Sentinel (KQL)

