Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAn Azure DNS Zone was modified Informational Cloud
An Azure DNS zone has been changed or removed, which may indicate malicious activity or a misconfiguration.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol: DNS (T1071.004)Required data: Azure Audit LogAttacker's goals: Take control of DNS zones to redirect traffic to malicious websites.Investigative actions: Verify whether the identity should be making this action.* Check what Azure DNS zones were changed or removed.