Nessus Authenticated Scan on AAD-Joined Device
Detects successful network or explicit credential logons (4624/4648) on Windows workstations where the username or workstation name contains keywords associated with Tenable Nessus scanning activity, indicating an authenticated vulnerability scan.
Microsoft Sentinel (KQL)

