LoFP LoFP / application deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.

Techniques

Sample rules

Azure Application Deleted

Description

Identifies when a application is deleted in Azure.

Detection logic

condition: selection
selection:
  properties.message:
  - Delete application
  - Hard Delete application