Failed Audit Policy Change Attempts
Detects failed attempts to change the system audit policy. This could indicate an adversary attempting to disable or modify security monitoring to evade detection.
Microsoft Sentinel (KQL)

Detects failed attempts to change the system audit policy. This could indicate an adversary attempting to disable or modify security monitoring to evade detection.

Already have an account?