kevmap

Log sources › azure:policy

azure:policy

Inverted view: what can be detected if this is the log you have. Identity Provider

3
channels
3
analytics
2
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
DisableAuditLogs or ConditionalAccess logging changes DC0069 Cloud Service Modification AN0802 1
DisableMfaPolicy or change to ConditionalAccess rules DC0010 User Account Modification AN0892 0
UpdatePolicy DC0069 Cloud Service Modification AN0290 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1556 Modify Authentication Processdefense impairment, persistence, credential access122
T1685.002 Disable or Modify Cloud Logdefense impairment30

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2020-12812Fortinet FortiOS T1556 Mapped
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1556 Mapped