Azure diagnostic configuration deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Hours
Required Data
Azure Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Log Tampering Analytics
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)
Severity
Informational
Description
An attacker might delete the Azure diagnostic settings to evade detection.
Attacker's Goals
Evade detection.
Investigative actions
Check the identity and its actions after the deletion action.
PreviousAzure device code authentication flow used
NextAzure domain federation settings modification attempt
Was this helpful?
