Cloud resource logging was disabled
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Data Detection & Response
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)
Severity
Informational
Description
Cloud resource logging was disabled.
Attacker's Goals
Avoiding detection of their activities by limiting the amount of data collected.
This action may be preliminary to resource deletion or data exhilaration from the resource.
Setting the stage for further attacks, like a Ransomware Attack.
Investigative actions
Confirm that the identity intended to disable logging on this resource.
Follow further actions done by the identity.
Monitor other (non-disabled) activity logs related to this resource.
Variations
Was this helpful?
