Analytics BIOC Informational

Cloud resource logging was disabled

Cloud resource logging was disabled.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Logs (T1562.008)
Detector tags: Cloud Data Asset Disaster Recovery Risks Cloud Data Asset Protection Tampering Data Detection & Response
Attacker's goals:

Avoiding detection of their activities by limiting the amount of data collected. This action may be preliminary to resource deletion or data exhilaration from the resource. Setting the stage for further attacks, like a Ransomware Attack.

Investigative actions:

Confirm that the identity intended to disable logging on this resource. Follow further actions done by the identity. Monitor other (non-disabled) activity logs related to this resource.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Cloud resource logging was disabled - failed attempt Informational
  • Cloud resource logging was disabled on an Azure DB/storage resource Informational
  • Cloud resource logging was disabled on a GCP DB/storage resource Low (parent: Informational)