Analytics BIOC Informational

An Azure DNS Zone was modified

An Azure DNS zone has been changed or removed, which may indicate malicious activity or a misconfiguration.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol: DNS (T1071.004)
Attacker's goals:

Take control of DNS zones to redirect traffic to malicious websites.

Investigative actions:

Verify whether the identity should be making this action.* Check what Azure DNS zones were changed or removed.

Test period:
N/A (single event)
Deduplication:
5 Days