Analytics BIOC
Informational
✕
Soft delete of cloud storage configuration was disabled
A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Detector tags: Cloud Data Asset Disaster Recovery Risks Cloud Data Asset Protection Tampering Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:
Impair the ability of the cloud environment to recover in disaster scenarios.
Investigative actions:
Check if the identity intended to disable soft delete for this storage account. Check if the identity performed additional malicious operations in the cloud environment.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day