Techniques
Sample rules
Azure Firewall Modified or Deleted
- source: sigma
- technicques:
- t1686
- t1686.001
Description
Identifies when a firewall is created, modified, or deleted.
Detection logic
condition: selection
selection:
operationName:
- MICROSOFT.NETWORK/AZUREFIREWALLS/WRITE
- MICROSOFT.NETWORK/AZUREFIREWALLS/DELETE