For the complete documentation index, see llms.txt. This page is also available as Markdown.

An Azure DNS Zone was modified

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Command and Control (TA0011)

ATT&CK Technique

Application Layer Protocol: DNS (T1071.004)

Severity

Informational

Description

An Azure DNS zone has been changed or removed, which may indicate malicious activity or a misconfiguration.

Attacker's Goals

  • Take control of DNS zones to redirect traffic to malicious websites.

Investigative actions

  • Verify whether the identity should be making this action.* Check what Azure DNS zones were changed or removed.

Was this helpful?