{"id":"af6925b0-8826-47f1-9324-337507a0babd","title":"Azure DNS Zone Modified or Deleted","description":"Identifies when DNS zone is modified or deleted.","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-08","modified":"2022-08-23","tags":["attack.impact","attack.t1565.001"],"technique_ids":["T1565.001"],"logsource":{"product":"azure","service":"activitylogs"},"falsepositives":["DNS zone modified and deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.","DNS zone modification from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule."],"references":["https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes"],"source_path":"rules/cloud/azure/activity_logs/azure_dns_zone_modified_or_deleted.yml","source_sha256":"f754f1ad7a1abafd4ebd93c005b55b8996212e7344294ad26755268e9a6a7867","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/activity_logs/azure_dns_zone_modified_or_deleted.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Azure DNS Zone Modified or Deleted\nid: af6925b0-8826-47f1-9324-337507a0babd\nstatus: test\ndescription: Identifies when DNS zone is modified or deleted.\nreferences:\n    - https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes\nauthor: Austin Songer @austinsonger\ndate: 2021-08-08\nmodified: 2022-08-23\ntags:\n    - attack.impact\n    - attack.t1565.001\nlogsource:\n    product: azure\n    service: activitylogs\ndetection:\n    selection:\n        operationName|startswith: 'MICROSOFT.NETWORK/DNSZONES'\n        operationName|endswith:\n            - '/WRITE'\n            - '/DELETE'\n    condition: selection\nfalsepositives:\n    - DNS zone modified and deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.\n    - DNS zone modification from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1565.001","id":"T1565.001","name":"Stored Data Manipulation","page":"techniques/enterprise/T1565.001/"}],"data_path":"data/detection-rules/af6925b0-8826-47f1-9324-337507a0babd.json","kind":"sigma"}
