Techniques
Sample rules
Azure Kubernetes Events Deleted
- source: sigma
- technicques:
- t1562
- t1562.001
Description
Detects when Events are deleted in Azure Kubernetes. An adversary may delete events in Azure Kubernetes in an attempt to evade detection.
Detection logic
condition: selection
selection:
operationName: MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/EVENTS.K8S.IO/EVENTS/DELETE