services / Azure / Microsoft Sentinel threat intelligence indicator bulk delete
Bulk-deletes threat-intelligence indicators (IOCs) in Microsoft Sentinel in a single operation.
Indicators are a detection input; bulk removal degrades coverage at scale but does not disable the platform, so this is MEDIUM.
Microsoft.SecurityInsights/threatintelligence/indicators/bulkDelete/action
Bulk-deleting indicators strips IOCs from the SIEM en masse, degrading detection of known-malicious infrastructure at scale.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog