Cloud Bucket Hijacking - Logging Sink Rerouted to External Storage Destination

This rule detects successful configuration modifications to diagnostic settings or storage services where the destination resource is identified as being outside of the organization's trusted subscriptions or expected storage naming conventions. This activity may indicate an adversary attempting to exfiltrate logs or data to an attacker-controlled storage account.