Skip to content

Compliance Rules

2 detection rules in this category.

RuleSeverityMITRESource
Audit logging config changedCriticalT1562.008AuditLog
DLP policy deletedCriticalT1562.001AuditLog

Audit logging config changed

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1562.008 (Defense Evasion)

Audit log configuration changed - possible tampering

Conditions
  • Match: all
  • Operation Equals Set-AdminAuditLogConfig

DLP policy deleted

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1562.001 (Defense Evasion)

DLP policy deleted - data protection removed

Conditions
  • Match: all
  • Operation Equals Remove-DlpCompliancePolicy