Merge PR #5542 from @peterydzynski - remove Azure Application Credential Modified

remove: Azure Application Credential Modified - superseeded by cbb67ecc-fb70-4467-9350-c910bdf7c628

---------

Co-authored-by: nasbench <nasbench@users.noreply.github.com>
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
This commit is contained in:
peterydzynski
2025-10-17 06:14:11 -04:00
committed by GitHub
parent 84425b8889
commit 8b41e6bfdf
@@ -1,12 +1,12 @@
title: Azure Application Credential Modified
id: cdeef967-f9a1-4375-90ee-6978c5f23974
status: test
status: deprecated
description: Identifies when a application credential is modified.
references:
- https://www.cloud-architekt.net/auditing-of-msi-and-service-principals/
author: Austin Songer @austinsonger
date: 2021-09-02
modified: 2022-10-09
modified: 2025-10-17
tags:
- attack.impact
logsource:
@@ -14,7 +14,7 @@ logsource:
service: activitylogs
detection:
selection:
properties.message: 'Update application - Certificates and secrets management'
properties.message: 'Update application Certificates and secrets management'
condition: selection
falsepositives:
- Application credential added may be performed by a system administrator.