Techniques
Sample rules
Azure Network Firewall Policy Modified or Deleted
- source: sigma
- technicques:
- t1562
- t1562.007
Description
Identifies when a Firewall Policy is Modified or Deleted.
Detection logic
condition: selection
selection:
operationName:
- MICROSOFT.NETWORK/FIREWALLPOLICIES/WRITE
- MICROSOFT.NETWORK/FIREWALLPOLICIES/JOIN/ACTION
- MICROSOFT.NETWORK/FIREWALLPOLICIES/CERTIFICATES/ACTION
- MICROSOFT.NETWORK/FIREWALLPOLICIES/DELETE