services / Azure / Log Analytics workspace data purge
Deletes specified data records by query from a Log Analytics workspace.
Query-targeted deletion of individual log records is the classic anti-forensics primitive; it removes evidence at row granularity, so the operation is HIGH.
Microsoft.OperationalInsights/workspaces/purge/action
Deletes matching log records by query, letting an attacker surgically erase the traces of their own activity and defeat the audit trail.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog