New Secret/Certificate Added to Existing App/Service Principal

Detects the addition of a new client secret or certificate to an existing Microsoft Entra ID (formerly Azure AD) application or service principal. This behavior is often used by adversaries to establish persistence following the compromise of an existing identity with administrative permissions, allowing continued access even if the original compromised credentials are revoked.