Rules Contributing to Suspicious Azure Firewall Activity Alert

The following rules are used to identify suspicious Azure firewall activity. Any one or more of these will trigger the Suspicious Azure Firewall Activity Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Azure Firewall Rule Configuration Modified or Deleted

Identifies when a Firewall Rule Configuration is Modified or Deleted.

Azure Firewall Rule Collection Modified or Deleted

Identifies when Rule Collections (Application, NAT, and Network) is being modified or deleted.

Azure Firewall Modified or Deleted

Identifies when a firewall is created, modified, or deleted.

Azure Network Firewall Policy Modified or Deleted

Identifies when a Firewall Policy is Modified or Deleted.