services / Azure / Microsoft Sentinel analytics rule
A Microsoft Sentinel analytics (alert) rule that queries ingested telemetry on a schedule and raises alerts/incidents when its detection logic matches. These rules are the primary detection mechanism of the SIEM.
Analytics rules are the SOC's detection backbone; tampering with or removing them creates blind spots across the security-monitoring function, so the resource type is inherently HIGH.
Microsoft.SecurityInsights/alertRules/delete
Removing an analytics rule permanently stops the detections it produced, blinding the SOC to the behaviors it covered.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog