Analytics BIOC Low

An Azure Firewall policy deletion

An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562)
Attacker's goals:

Exfiltrate information, network persistence of a service/resource.

Investigative actions:

Check which subnets or specific IP addresses were affected by the change. Check which services were accessed after the firewall change and via which protocols or network traffic.

Test period:
N/A (single event)
Deduplication:
3 Hours