Elastic medium stable kql
Azure Recovery Services Resource Deleted
Identifies the deletion of Azure Recovery Services resources. Azure Recovery Services vaults contain data for copies of VMs, workloads, servers, and other resources regarding Infrastructure as a Service (IaaS). Adversaries may delete these recovery services to impact backup capabilities during stable operations or to inhibit disaster recovery services during ransom-based attacks or operational disruptions.
Detection Logic
event.dataset:azure.activitylogs and
azure.activitylogs.operation_name:MICROSOFT.RECOVERYSERVICES/*/DELETE and
event.outcome:(Success or success) Field Validations
Loading…
Comments (0)
Loading comments...