services / Azure / Network Watcher flow log configuration

Configures NSG flow logging for a target resource, controlling whether network traffic flow records are captured and where they are stored.

Used both to enable flow logging (collection) and to disable it on an existing target, removing the network traffic audit trail.


Microsoft.​Network/​networkWatchers/​configureFlowLog/​action

Disabling flow logging on an NSG before or during other malicious network activity removes the traffic-level record that would otherwise reveal that activity, a textbook detection-evasion move. Can also redirect logs to an attacker-controlled storage destination.

Risks

Scope: MEDIUM

This privilege may grant access to confidential data, or its exploit can incur operational cost.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​Network
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog