Azure Suppression Rule Created
Description
Identifies when a suppression rule is created in Azure. Adversary's could attempt this to evade detection.
Query · sigma
selection: operationName: MICROSOFT.SECURITY/ALERTSSUPPRESSIONRULES/WRITE condition: selection
Known false positives
- Suppression Rule being created may be performed by a system administrator.
- Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Suppression Rule created from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.