Storm-3168 (JADEPUFFER) Service principal auth followed by mass Azure enumeration (leaked-secret proxy)
Detects a suspicious sequence of behavior where an Azure service principal authenticates and immediately performs broad reconnaissance (enumeration) across multiple subscriptions and resource types. This pattern is often indicative of an adversary using a compromised service principal credential to map out an environment.
Microsoft Sentinel (KQL)

