The Blind Spot in the Watchtower: Detections for When Someone Attacks Your Sentinel
ID: d19ceddc-778d-5b41-8a57-82bf289cc40c
STIX ID: report--d19ceddc-778d-5b41-8a57-82bf289cc40c
Feed Name: Detect FYI
This article describes how attackers can subvert Microsoft Sentinel (the SIEM) — for example by disabling analytic rules, shortening retention, deleting diagnostic settings, changing connectors, granting themselves roles, tampering playbooks/watchlists, editing incidents, or deleting the workspace — and provides nine corresponding Kusto queries and operational recommendations to detect those tampering actions and reduce noise using an approved-admin watchlist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
