Storage Analytics logging disabled
Storage Analytics logging disabled
Event
The former catalog label Microsoft.Storage/storageAccounts/stopLogging/action could not be verified in current Microsoft operation documentation. Legacy Storage Analytics logging is configured per service through service properties, such as Set Blob Service Properties. Azure Monitor diagnostic settings are a separate collection path.
Security Context
Unauthorized disabling of active logging can impair cloud visibility (T1685.002). A legacy logging change does not prove all storage telemetry is disabled or delete historical logs. Approved migrations may turn off redundant collection.
Log Source
No native Azure Activity Log event with the former stopLogging/action name was verified. Investigate actual service-property changes and logging configuration; Azure Monitor diagnostic-setting changes are separate ARM operations. The configuration summary below is not a detection fixture.
Key Fields
| Field | Investigation value |
|---|---|
service, documentedOperation | Which storage service and documented configuration API are being discussed. |
logging.read, logging.write, logging.delete | Illustrative disabled categories; not claimed native audit field names. |
logging.retentionPolicy | Illustrative retention setting; historical records require separate inspection. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Identify the actual API and storage service, and compare previous/new read, write, and delete logging flags.
- Inspect Azure Monitor diagnostic settings, destinations, and historical Storage Analytics records independently.
- Confirm a real collection gap and approved migration context; do not build a detection around the unverified stopLogging/action string.
Sample Event
Synthetic scenario. The JSON is an explanatory configuration summary for disabling Blob Storage Analytics categories, not a native audit event or an executable REST request. The documented REST operation uses XML. This replaces the unsupported Activity Log example while preserving the page URL.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "illustrationType": "Configuration summary, not a native log or REST body", "service": "Azure Blob Storage", "documentedOperation": "Set Blob Service Properties", "logging": { "version": "1.0", "read": false, "write": false, "delete": false, "retentionPolicy": { "enabled": false } }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...