Azure Diagnostic Setting Modification Spike
This rule detects a spike in modifications or creations of Azure Diagnostic Settings within a one-hour window. A high volume of 'Diagnostic Setting' operations by a single caller could indicate an attempt to alter logging configurations, potentially to impair defenses or hide malicious activity.
Microsoft Sentinel (KQL)

