Using the software AppID's from the Huntress Rouge Apps page, I created this metric to detect the following potentially malicious Microsoft 365 Apps:
eM Client
PerfectData
Software Newsletter
Software Supermailer
rclone
CloudSponge
SigParser
Mail_Backup
ServicePrincipals[?contains(
["e9a7fea1-1cc0-4cd9-a31b-9137ca5deedd", "ff8d92dc-3d82-41d6-bcbd-b9174d163620", "a245e8c0-b53c-4b67-9b45-751d1dff8e6b", "b15665d9-eda6-4092-8539-0eec376afd59", "a43e5392-f48b-46a4-a0f1-098b5eeb4757", "caffae8c-0882-4c81-9a27-d1803af53a40", "2ef68ccc-8a4d-42ff-ae88-2d7bb89ad139"]
, appId)].[appDisplayName, join(
:
, [``, to_string(createdDateTime)])]