{"id":"410d2a41-1e6d-452f-85e5-abdd8257a823","title":"Azure Application Deleted","description":"Identifies when a application is deleted in Azure.","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-09-03","modified":"2022-10-09","tags":["attack.impact","attack.t1489"],"technique_ids":["T1489"],"logsource":{"product":"azure","service":"activitylogs"},"falsepositives":["Application being deleted may be performed by a system administrator.","Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.","Application deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule."],"references":["https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#application-proxy"],"source_path":"rules/cloud/azure/activity_logs/azure_application_deleted.yml","source_sha256":"a2bbef2ac6d1001d797435e01c0a87920aca46f53b502aa4ec150848b1acfad3","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/activity_logs/azure_application_deleted.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Azure Application Deleted\nid: 410d2a41-1e6d-452f-85e5-abdd8257a823\nstatus: test\ndescription: Identifies when a application is deleted in Azure.\nreferences:\n    - https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#application-proxy\nauthor: Austin Songer @austinsonger\ndate: 2021-09-03\nmodified: 2022-10-09\ntags:\n    - attack.impact\n    - attack.t1489\nlogsource:\n    product: azure\n    service: activitylogs\ndetection:\n    selection:\n        properties.message:\n            - Delete application\n            - Hard Delete application\n    condition: selection\nfalsepositives:\n    - Application being deleted may be performed by a system administrator.\n    - Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.\n    - Application deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1489","id":"T1489","name":"Service Stop","page":"techniques/enterprise/T1489/"}],"data_path":"data/detection-rules/410d2a41-1e6d-452f-85e5-abdd8257a823.json","kind":"sigma"}
