services / Azure / Microsoft Sentinel analytics rule
A Microsoft Sentinel analytics (alert) rule that queries ingested telemetry on a schedule and raises alerts/incidents when its detection logic matches. These rules are the primary detection mechanism of the SIEM.
Analytics rules are the SOC's detection backbone; tampering with or removing them creates blind spots across the security-monitoring function, so the resource type is inherently HIGH.
Microsoft.SecurityInsights/alertRules/write
Updating a rule lets an attacker disable it or narrow its detection logic to carve out blind spots around their own activity, defeating detection without leaving an obvious deletion.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security