Logging and detection

Azure records control-plane activity in the Activity Log and fans detection out through Azure Monitor (diagnostic settings into Log Analytics), Defender for Cloud, and Microsoft Sentinel. An operator working to stay unseen degrades these in order of leverage: stop the export that feeds the SIEM, downgrade the posture service that raises alerts, and disable the analytics rules that would fire. The Activity Log itself is retained immutably for 90 days, so the real game is controlling what reaches long-term and alerting sinks, and preferring operations that never land there.

Pages#

  • Activity Log: what the subscription operation log does and does not capture, and cutting its export to downstream sinks.
  • Azure Monitor: deleting diagnostic settings to stop resource logs, and stealing Log Analytics workspace keys.
  • Defender for Cloud: downgrading plans and policy to blind cloud threat detection.
  • Sentinel: disabling analytics rules and removing data connectors to blind the SIEM.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more