Azure Diagnostic Settings Deletion - Defense Evasion
Detects the successful deletion of diagnostic settings in Azure, which may be an attempt by an adversary to impair logging and hide malicious activity.
Microsoft Sentinel (KQL)

Detects the successful deletion of diagnostic settings in Azure, which may be an attempt by an adversary to impair logging and hide malicious activity.

Already have an account?