AN0801
Analytic 0801
IaaS
Cloud API events where logging services are stopped, deleted, or modified in a way that disables audit visibility. Defender view: unauthorized StopLogging, DeleteTrail, or UpdateSink operations correlated with privileged user activity.
AWS:CloudTrail
Stop logging for an existing CloudTrail
gcp:config
UpdateSink request modifying log export destinations
[AdminRoles]
Define which roles are authorized to stop or modify logging.
[RegionScope]
Adjust monitoring to ensure multi-region logging tampering is caught.
AN0802
Analytic 0802
Identity Provider
Disabling or modifying sign-in or audit log collection for user activities. Defender view: policy or configuration updates removing logging coverage for critical accounts.
azure:policy
DisableAuditLogs or ConditionalAccess logging changes
[CriticalAccounts]
Tune to prioritize logging changes that affect administrative or high-value accounts.
AN0803
Analytic 0803
Office Suite
Disabling mailbox or tenant-level audit logging, often using Set-MailboxAuditBypassAssociation or downgrading license tiers. Defender view: sudden absence of mailbox activity logging for monitored users.
m365:unified
Set-MailboxAuditBypassAssociation or disabling Advanced Auditing
[UserScope]
Tune alerts for users where mailbox auditing should always remain enabled.
AN0804
Analytic 0804
SaaS
Disabling or altering security and audit logs in SaaS admin panels (e.g., Slack, Zoom, Salesforce). Defender view: API calls or admin console changes that stop event exports or logging integrations.
saas:audit
Log export integration removed or disabled
[IntegrationScope]
Define which SaaS log integrations are required and alert if removed.