Exchange audit log disabled
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection, Email
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)
Severity
Low
Description
A user disabled the Exchange audit log. This may indicate an attempt to evade detection.
Attacker's Goals
An attacker is attempting to evade detection.
Investigative actions
Follow further actions done by the account.
Verify that the configuration change was expected.
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Was this helpful?
