Mass Storage Account ListKeys burst by single service principal
Detects a service principal or user account performing a burst of 'ListKeys' operations across multiple Azure Storage accounts. This behavior is indicative of an attacker attempting to dump access keys for multiple storage accounts after initial compromise or privilege escalation to gain further access to sensitive cloud data.
Microsoft Sentinel (KQL)

