logo

Azure Logging just Changed - Your Detections May be Missing it by Alex Groyz

ID: d07d4eff-54b9-5583-b784-111dfbaae2e2

STIX ID: report--d07d4eff-54b9-5583-b784-111dfbaae2e2

Feed Name: Vectra AI Blog

Threat Score
35/100

Date Published: 2026-04-20

Date Updated: 2026-05-01

...
...

This report explains that Azure's move from VM-based diagnostics extensions to centralized Data Collection Rules (DCRs) with the Azure Monitor Agent can allow a single API call to silently disable logging across multiple VMs, producing delayed or misattributed activity in Azure Activity Logs and creating detection gaps; defenders are advised to monitor DCR and DCR-association events and update detections accordingly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.