{"id":"46530378-f9db-4af9-a9e5-889c177d3881","title":"Azure Device or Configuration Modified or Deleted","description":"Identifies when a device or device configuration in azure is modified or deleted.","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-09-03","modified":"2022-10-09","tags":["attack.impact","attack.t1485","attack.t1565.001"],"technique_ids":["T1485","T1565.001"],"logsource":{"product":"azure","service":"activitylogs"},"falsepositives":["Device or device configuration being modified or deleted may be performed by a system administrator.","Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.","Device or device configuration modified or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule."],"references":["https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory"],"source_path":"rules/cloud/azure/activity_logs/azure_device_or_configuration_modified_or_deleted.yml","source_sha256":"b7eba6d552a7179a1c2878b45648d39798dd5f5c8fd8c7cac970f8c88b8ead65","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/activity_logs/azure_device_or_configuration_modified_or_deleted.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Azure Device or Configuration Modified or Deleted\nid: 46530378-f9db-4af9-a9e5-889c177d3881\nstatus: test\ndescription: Identifies when a device or device configuration in azure is modified or deleted.\nreferences:\n    - https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities#core-directory\nauthor: Austin Songer @austinsonger\ndate: 2021-09-03\nmodified: 2022-10-09\ntags:\n    - attack.impact\n    - attack.t1485\n    - attack.t1565.001\nlogsource:\n    product: azure\n    service: activitylogs\ndetection:\n    selection:\n        properties.message:\n            - Delete device\n            - Delete device configuration\n            - Update device\n            - Update device configuration\n    condition: selection\nfalsepositives:\n    - Device or device configuration being modified or deleted may be performed by a system administrator.\n    - Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.\n    - Device or device configuration modified or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1485","id":"T1485","name":"Data Destruction","page":"techniques/enterprise/T1485/"},{"key":"enterprise/T1565.001","id":"T1565.001","name":"Stored Data Manipulation","page":"techniques/enterprise/T1565.001/"}],"data_path":"data/detection-rules/46530378-f9db-4af9-a9e5-889c177d3881.json","kind":"sigma"}
