You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Identifies the deletion of a Network Watcher in Azure. Network Watcher is used to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network. An adversary may delete a network watcher in an attempt to evade defenses.
event.module:azure and event.dataset:azure.activitylogs and event.category:Administrative and azure.activitylogs.operation_name:MICROSOFT.NETWORK/NETWORKWATCHERS/DELETE and event.outcome:Success
Example Data
The text was updated successfully, but these errors were encountered:
Description
Identifies the deletion of a Network Watcher in Azure. Network Watcher is used to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network. An adversary may delete a network watcher in an attempt to evade defenses.
Required Info
Eventing Sources:
filebeat-*
Platforms
azure
Target ECS Version:
1.5.0
New fields required in ECS for this?
Related issues or PRs
Optional Info
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-monitoring-overview
Syntax
Example Data
The text was updated successfully, but these errors were encountered: