Analytic rule catalog
Pathlock TDnR - ABAP Source Code Changes
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01 |
| Rulename | Pathlock TDnR - ABAP Source Code Changes |
| Description | Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer. |
| Severity | High |
| Tactics | Persistence DefenseEvasion |
| Techniques | T1505 T1562 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01.json |
Pathlock_TDnR_CL
| where DataSource == "ABAP_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
tactics:
- Persistence
- DefenseEvasion
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
incidentConfiguration:
createIncident: true
groupingConfiguration:
groupByAlertDetails: []
groupByEntities: []
matchingMethod: AnyAlert
groupByCustomDetails: []
enabled: true
reopenClosedIncident: false
lookbackDuration: 5h
queryPeriod: 1h
severity: High
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml
queryFrequency: 1h
kind: Scheduled
description: Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01
triggerOperator: gt
status: Available
relevantTechniques:
- T1505
- T1562
suppressionDuration: 5h
version: 1.0.0
triggerThreshold: 0
suppressionEnabled: false
name: Pathlock TDnR - ABAP Source Code Changes
eventGroupingSettings:
aggregationKind: SingleAlert
entityMappings:
- entityType: Account
fieldMappings:
- columnName: Bname
identifier: Name
- entityType: Host
fieldMappings:
- columnName: Hostname
identifier: HostName
- entityType: IP
fieldMappings:
- columnName: SrcIp
identifier: Address
query: |
Pathlock_TDnR_CL
| where DataSource == "ABAP_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01",
"customDetails": null,
"description": "Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.",
"displayName": "Pathlock TDnR - ABAP Source Code Changes",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"ABAP_CHANGES\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"DefenseEvasion",
"Persistence"
],
"techniques": [
"T1505",
"T1562"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}