Detect sudden activity from long-dormant Service Principals and App Registrations that may indicate compromised client secrets or abandoned credentials.
Monitor high-privilege Azure RBAC grant operations (Owner, Contributor, User Access Administrator) in AzureActivity logs using proactive KQL alert rules.
Detect credential theft targeting the Local Security Authority Subsystem Service (LSASS) via native LOLBINs like comsvcs.dll and Sysinternals ProcDump in KQL.