An Azure Firewall policy deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Hours
Required Data
Azure Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685)
Severity
Low
Description
An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses.
Attacker's Goals
Exfiltrate information, network persistence of a service/resource.
Investigative actions
Check which subnets or specific IP addresses were affected by the change.
Check which services were accessed after the firewall change and via which protocols or network traffic.
PreviousAn Azure DNS Zone was modified
NextAn Azure Firewall rule collection group was modified or deleted
Was this helpful?
