Named Pipe Remote Access via JsonVMAccessExtension
Detects named pipe activity with remote access enabled, initiated by JsonVMAccessExtension.exe running as SYSTEM. This may indicate abuse of the Azure VM Access Extension for unauthorized remote access.
Microsoft Sentinel (KQL)

