Analytics BIOC Informational

Azure Automation Runbook Deletion

An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Impact (TA0040)
ATT&CK techniques: Impair Defenses (T1562) Service Stop (T1489)
Attacker's goals:

Stop business services.

Investigative actions:

Check which runbook was deleted and whether it is malicious or valid.

Test period:
N/A (single event)
Deduplication:
1 Day