Analytics BIOC
Low
✕
An Azure Firewall policy deletion
An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562)
Attacker's goals:
Exfiltrate information, network persistence of a service/resource.
Investigative actions:
Check which subnets or specific IP addresses were affected by the change. Check which services were accessed after the firewall change and via which protocols or network traffic.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Hours