For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cloud storage delete protection disabled

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Data Detection & Response

ATT&CK Tactic

Impact (TA0040)

ATT&CK Technique

Inhibit System Recovery (T1490)

Severity

Informational

Description

Delete protection of a cloud storage resource was disabled.

Attacker's Goals

  • Impair built-in protection of the cloud environment.

  • This action may be a preliminary action before deleting the cloud resource itself.

Investigative actions

  • Confirm that the identity intended to disable deletion protection on this resource.

  • Follow further actions done by the identity.

  • Monitor this resource for other suspicious activities.

Variations

Cloud storage delete protection disabled by an unusual identity

Synopsis

Field
Value

ATT&CK Tactic

Impact (TA0040)

ATT&CK Technique

Inhibit System Recovery (T1490)

Severity

Informational

Description

Delete protection of a cloud storage resource was disabled by an unusual identity.

Attacker's Goals

  • Impair built-in protection of the cloud environment.

  • This action may be a preliminary action before deleting the cloud resource itself.

Investigative actions

  • Confirm that the identity intended to disable deletion protection on this resource.

  • Follow further actions done by the identity.

  • Monitor this resource for other suspicious activities.

Was this helpful?