Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapCloud resource logging was disabled Informational Cloud 3 variations
Cloud resource logging was disabled.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Logs (T1562.008)Required data: Azure Audit Log Gcp Audit LogDetector tags: Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Data Detection & ResponseAttacker's goals: Avoiding detection of their activities by limiting the amount of data collected. This action may be preliminary to resource deletion or data exhilaration from the resource. Setting the stage for further attacks, like a Ransomware Attack.Investigative actions: Confirm that the identity intended to disable logging on this resource. Follow further actions done by the identity. Monitor other (non-disabled) activity logs related to this resource.Variations
Cloud resource logging was disabled - failed attempt
Informational overridden
A failed attempt to disable cloud resource logging. overridden
Cloud resource logging was disabled on an Azure DB/storage resource
Informational overridden
Cloud resource logging was disabled on a DB/storage resource. overridden
Cloud resource logging was disabled on a GCP DB/storage resource
Low overridden
Cloud resource logging was disabled on a DB/storage resource. overridden