cd

5 min read

Azure Activity: Diagnostic Setting Deleted

Description

This query detects when an Azure resource’s diagnostic setting has been deleted.

Azure Diagnostic Settings are critical for logging security events, monitoring performance, and maintaining compliance. If an attacker or unauthorized user deletes these settings, it can prevent security teams from detecting malicious activity, making it a defense evasion technique.

Query

AzureActivity
| where OperationNameValue contains "MICROSOFT.INSIGHTS/DIAGNOSTICSETTINGS/DELETE"
| where ActivityStatusValue == "Start"
| extend props = parse_json(Properties)
| extend entity = props.entity
| extend resource = props.resource
| project TimeGenerated, CorrelationId, Caller, CallerIpAddress, SubscriptionId, ResourceGroup, resource, entity

MITRE ATT&CK

IDTechniqueTactic
T1562.008Impair Defenses: Disable or Modify Cloud LogsDefense Evasion

Analytic Rule

  • Yaml:
  • ARM:

Notes