Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAzure account deletion by a non-standard account Low Identity Threat Module, SaaS Threat Detection 2 variations
An Azure AD account deletion was performed by a user that doesn't typically delete users.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Account Access Removal (T1531)Required data: AzureAD Audit LogAttacker's goals: Interrupt availability and access to Azure by deleting access accounts.Investigative actions: Follow further actions by the initiator. Check what services, groups and applications are affected by the deleted user being removed. Check if the deleted user had a privileged role.Variations
Azure account deletion by a non-standard account with high administrative activity
Informational overridden
An Azure AD account deletion was performed by an identity with high administrative activity that doesn't typically delete users. overridden
A suspicious Azure account deletion by a non-standard account
Medium overridden
An Azure AD account deletion was performed by a user that doesn't typically delete users in a suspicious manner. overridden