logo

The Blind Spot in the Watchtower: Detections for When Someone Attacks Your Sentinel

ID: d19ceddc-778d-5b41-8a57-82bf289cc40c

STIX ID: report--d19ceddc-778d-5b41-8a57-82bf289cc40c

Feed Name: Detect FYI

Date Published: 2026-07-03

Date Updated: 2026-07-03

Author: Rohitashokgowd

...
...

This article describes how attackers can subvert Microsoft Sentinel (the SIEM) — for example by disabling analytic rules, shortening retention, deleting diagnostic settings, changing connectors, granting themselves roles, tampering playbooks/watchlists, editing incidents, or deleting the workspace — and provides nine corresponding Kusto queries and operational recommendations to detect those tampering actions and reduce noise using an approved-admin watchlist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.