For the complete documentation index, see llms.txt. This page is also available as Markdown.

An Azure Firewall policy deletion

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Hours

Required Data

Azure Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Low

Description

An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses.

Attacker's Goals

Exfiltrate information, network persistence of a service/resource.

Investigative actions

  • Check which subnets or specific IP addresses were affected by the change.

  • Check which services were accessed after the firewall change and via which protocols or network traffic.

Was this helpful?