LoFP LoFP / dns zone modification from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.

Techniques

Sample rules

Azure DNS Zone Modified or Deleted

Description

Identifies when DNS zone is modified or deleted.

Detection logic

condition: selection
selection:
  operationName|endswith:
  - /WRITE
  - /DELETE
  operationName|startswith: MICROSOFT.NETWORK/DNSZONES