services / Azure / Log Analytics saved search
A saved search query in a workspace; when paired with a schedule it forms a Log Analytics alert rule that drives detections.
Saved searches back scheduled alert rules, so tampering with or removing them degrades detection logic; HIGH.
Microsoft.OperationalInsights/workspaces/savedSearches/write
Rewriting a saved search can neuter the detection query behind an alert rule so malicious activity no longer matches.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog