services / Azure / Microsoft Sentinel threat intelligence indicator
An individual threat-intelligence indicator (IOC) in Microsoft Sentinel that detections match ingested telemetry against.
Indicators are a detection input; altering or removing them narrows coverage but does not disable the platform, so this is MEDIUM.
Microsoft.SecurityInsights/threatintelligence/indicators/delete
Deleting an indicator removes an IOC the SIEM matches against, degrading detection coverage of known-malicious infrastructure.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog