Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0289 — Detection Strategy for Disable or Modify Cloud Log
DET0289

Detection Strategy for Disable or Modify Cloud Log

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0801 Analytic 0801
IaaS

Cloud API events where logging services are stopped, deleted, or modified in a way that disables audit visibility. Defender view: unauthorized StopLogging, DeleteTrail, or UpdateSink operations correlated with privileged user activity.

AWS:CloudTrail Stop logging for an existing CloudTrail gcp:config UpdateSink request modifying log export destinations
[AdminRoles] Define which roles are authorized to stop or modify logging.
[RegionScope] Adjust monitoring to ensure multi-region logging tampering is caught.
AN0802 Analytic 0802
Identity Provider

Disabling or modifying sign-in or audit log collection for user activities. Defender view: policy or configuration updates removing logging coverage for critical accounts.

azure:policy DisableAuditLogs or ConditionalAccess logging changes
[CriticalAccounts] Tune to prioritize logging changes that affect administrative or high-value accounts.
AN0803 Analytic 0803
Office Suite

Disabling mailbox or tenant-level audit logging, often using Set-MailboxAuditBypassAssociation or downgrading license tiers. Defender view: sudden absence of mailbox activity logging for monitored users.

m365:unified Set-MailboxAuditBypassAssociation or disabling Advanced Auditing
[UserScope] Tune alerts for users where mailbox auditing should always remain enabled.
AN0804 Analytic 0804
SaaS

Disabling or altering security and audit logs in SaaS admin panels (e.g., Slack, Zoom, Salesforce). Defender view: API calls or admin console changes that stop event exports or logging integrations.

saas:audit Log export integration removed or disabled
[IntegrationScope] Define which SaaS log integrations are required and alert if removed.

Detected Techniques

1

Details

MITRE ID
DET0289
STIX ID
x-mitre-detection-strategy--f0190654-2eda-42a7-9a4d-6edc95aada02
Analytics
4
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.