Azure Sentinel Analytics Rule Creation or Update
Detects the creation or update of an Azure Sentinel analytics rule. This can indicate administrative activity related to security monitoring configuration. Monitoring these changes is crucial for detecting potential tampering with detection capabilities or the introduction of malicious rules.
Microsoft Sentinel (KQL)

