Azure Network Watcher Deletion

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2024-12-03
Category
Analytics Alert Reference
Order
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Hours

Required Data

  • Requires:
    • Azure Audit Log

Detection Modules

Cloud

Detector Tags

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Severity

Low

Description

Network Watchers are used for monitoring and diagnosing for Azure resources. An attacker might use this technique to avoid security mitigations.

Attacker's Goals

Avoid security mitigations and detections.

Investigative actions

  • Check which devices are monitored by the deleted Network Watcher.