Techniques
Sample rules
Azure DNS Zone Modified or Deleted
- source: sigma
- technicques:
- t1565
- t1565.001
Description
Identifies when DNS zone is modified or deleted.
Detection logic
condition: selection
selection:
operationName|endswith:
- /WRITE
- /DELETE
operationName|startswith: MICROSOFT.NETWORK/DNSZONES