Techniques
Sample rules
Azure Firewall Rule Configuration Modified or Deleted
- source: sigma
- technicques:
Description
Identifies when a Firewall Rule Configuration is Modified or Deleted.
Detection logic
condition: selection
selection:
operationName:
- MICROSOFT.NETWORK/FIREWALLPOLICIES/RULECOLLECTIONGROUPS/WRITE
- MICROSOFT.NETWORK/FIREWALLPOLICIES/RULECOLLECTIONGROUPS/DELETE
- MICROSOFT.NETWORK/FIREWALLPOLICIES/RULEGROUPS/WRITE
- MICROSOFT.NETWORK/FIREWALLPOLICIES/RULEGROUPS/DELETE