An Azure Suppression Rule was created
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Azure Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Log Tampering Analytics
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685)
Severity
Informational
Description
An Azure Suppression Rule was created.
Attacker's Goals
Bypass security measures.
Investigative actions
Investigate the user's activity to determine the cause of the alert.
PreviousAn Azure SQL database was exported from a production subscription
NextAn Azure virtual network Device was modified
Was this helpful?
