{"id":"cbb67ecc-fb70-4467-9350-c910bdf7c628","title":"Added Credentials to Existing Application","description":"Detects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials.","author":"Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'","status":"test","level":"high","date":"2022-05-26","modified":"2025-07-18","tags":["attack.privilege-escalation","attack.t1098.001","attack.persistence"],"technique_ids":["T1098.001"],"logsource":{"product":"azure","service":"auditlogs"},"falsepositives":["When credentials are added/removed as part of the normal working hours/workflows"],"references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-credentials"],"source_path":"rules/cloud/azure/audit_logs/azure_app_credential_added.yml","source_sha256":"eeb9f4d13576ea50e0c2d9513f0b0be819d29dd9bccb0c4b5c07f10bfb78fbb1","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/audit_logs/azure_app_credential_added.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Added Credentials to Existing Application\nid: cbb67ecc-fb70-4467-9350-c910bdf7c628\nstatus: test\ndescription: Detects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials.\nreferences:\n    - https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-credentials\nauthor: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'\ndate: 2022-05-26\nmodified: 2025-07-18\ntags:\n    - attack.privilege-escalation\n    - attack.t1098.001\n    - attack.persistence\nlogsource:\n    product: azure\n    service: auditlogs\ndetection:\n    selection:\n        properties.message:\n            - Update application – Certificates and secrets management\n            - Update Service principal/Update Application\n    condition: selection\nfalsepositives:\n    - When credentials are added/removed as part of the normal working hours/workflows\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1098.001","id":"T1098.001","name":"Additional Cloud Credentials","page":"techniques/enterprise/T1098.001/"}],"data_path":"data/detection-rules/cbb67ecc-fb70-4467-9350-c910bdf7c628.json","kind":"sigma"}
