Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF026.004
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Cloud Audit Log Modification

A subject intentionally alters cloud audit records or exported cloud log data to conceal, misattribute, or misrepresent activity conducted within a cloud environment.

 

The subject may replace or modify log objects held in cloud storage, alter records within a log analytics workspace or data lake, manipulate a custom logging pipeline, or insert fabricated events into a downstream repository. Changes may affect the recorded identity, source address, operation, resource, timestamp, request parameters, or outcome.

 

Provider-maintained audit histories may prevent direct modification by tenant administrators. Investigators should therefore compare native provider records with exported copies, storage-object versions, logging-pipeline configurations, access records, and Security Information and Event Management (SIEM) data.