Azure Network Watcher Deletion

Cortex XSIAM Analytics Alert Reference by Alert name

Product
Cortex XSIAM
Last date published
2025-01-19
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Hours

Required Data

  • Requires:
    • Azure Audit Log

Detection Modules

Cloud

Detector Tags

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Severity

Low

Description

Network Watchers are used for monitoring and diagnosing for Azure resources. An attacker might use this technique to avoid security mitigations.

Attacker's Goals

Avoid security mitigations and detections.

Investigative actions

  • Check which devices are monitored by the deleted Network Watcher.