Analytics BIOC Low

Exchange audit log disabled

A user disabled the Exchange audit log. This may indicate an attempt to evade detection.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562) Impair Defenses: Disable or Modify Cloud Logs (T1562.008)
Attacker's goals:

An attacker is attempting to evade detection.

Investigative actions:

Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

Test period:
N/A (single event)
Deduplication:
1 Day