services / Azure / Network Watcher flow log configuration
Configures NSG flow logging for a target resource, controlling whether network traffic flow records are captured and where they are stored.
Used both to enable flow logging (collection) and to disable it on an existing target, removing the network traffic audit trail.
Microsoft.Network/networkWatchers/configureFlowLog/action
Disabling flow logging on an NSG before or during other malicious network activity removes the traffic-level record that would otherwise reveal that activity, a textbook detection-evasion move. Can also redirect logs to an attacker-controlled storage destination.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog