Sentinel Analytics Rule Disabled or Deleted - T1562.001
This rule detects unauthorized or suspicious modifications to Microsoft Sentinel alert rules. It specifically monitors for the deletion of alert rules or the disabling of existing rules via the Azure activity logs. Such actions may indicate an attempt by an adversary to impair security monitoring and defensive capabilities.
Microsoft Sentinel (KQL)

