Azure Sentinel Alert/Automation Rule Tampering via SecurityInsights
This rule monitors for unauthorized deletion or modification of Microsoft Sentinel alert rules and automation rules. Such actions are indicative of an attacker attempting to impair security monitoring, silence alerts, or disable automated responses to maintain persistence and evade detection.
Microsoft Sentinel (KQL)

