Azure Logging just Changed - Your Detections May be Missing it by Alex Groyz
ID: d07d4eff-54b9-5583-b784-111dfbaae2e2
STIX ID: report--d07d4eff-54b9-5583-b784-111dfbaae2e2
Feed Name: Vectra AI Blog
Threat Score
This report explains that Azure's move from VM-based diagnostics extensions to centralized Data Collection Rules (DCRs) with the Azure Monitor Agent can allow a single API call to silently disable logging across multiple VMs, producing delayed or misattributed activity in Azure Activity Logs and creating detection gaps; defenders are advised to monitor DCR and DCR-association events and update detections accordingly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
