Analytic rule catalog
Pathlock TDnR - ABAP Source Code Changes
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01 |
| Rulename | Pathlock TDnR - ABAP Source Code Changes |
| Description | Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer. |
| Severity | High |
| Tactics | Persistence DefenseEvasion |
| Techniques | T1505 T1562 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01.json |
Pathlock_TDnR_CL
| where DataSource == "ABAP_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
incidentConfiguration:
groupingConfiguration:
groupByAlertDetails: []
groupByCustomDetails: []
lookbackDuration: 5h
enabled: true
reopenClosedIncident: false
matchingMethod: AnyAlert
groupByEntities: []
createIncident: true
name: Pathlock TDnR - ABAP Source Code Changes
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01
triggerThreshold: 0
queryPeriod: 1h
query: |
Pathlock_TDnR_CL
| where DataSource == "ABAP_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
status: Available
eventGroupingSettings:
aggregationKind: SingleAlert
severity: High
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml
relevantTechniques:
- T1505
- T1562
tactics:
- Persistence
- DefenseEvasion
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Bname
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
- fieldMappings:
- identifier: Address
columnName: SrcIp
entityType: IP
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01",
"customDetails": null,
"description": "Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.",
"displayName": "Pathlock TDnR - ABAP Source Code Changes",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"ABAP_CHANGES\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"DefenseEvasion",
"Persistence"
],
"techniques": [
"T1505",
"T1562"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}