2026 Critical Cloud Control Plane Detection: Centralized Log Sink/Bucket Deletion or Public-Write Modification
Detects malicious attempts to delete or modify the access control settings of centralized cloud audit log storage, such as S3 buckets, Azure Log Analytics workspaces, or GCP log buckets. These actions aim to impair visibility into an adversary's activities, a common step in anti-forensics and data destruction workflows.
Microsoft Sentinel (KQL)

