Back
Id2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01
RulenamePathlock TDnR - ABAP Source Code Changes
DescriptionDetects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.
SeverityHigh
TacticsPersistence
DefenseEvasion
TechniquesT1505
T1562
Required data connectorsPathlock_TDnR
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml
Version1.0.0
Arm template2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01.json
Deploy To Azure
Pathlock_TDnR_CL
| where DataSource == "ABAP_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    groupByEntities: []
    enabled: true
    matchingMethod: AnyAlert
    groupByCustomDetails: []
    reopenClosedIncident: false
    lookbackDuration: 5h
    groupByAlertDetails: []
entityMappings:
- entityType: Account
  fieldMappings:
  - columnName: Bname
    identifier: Name
- entityType: Host
  fieldMappings:
  - columnName: Hostname
    identifier: HostName
- entityType: IP
  fieldMappings:
  - columnName: SrcIp
    identifier: Address
query: |
  Pathlock_TDnR_CL
  | where DataSource == "ABAP_CHANGES"
  | project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
            Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
            MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
suppressionEnabled: false
eventGroupingSettings:
  aggregationKind: SingleAlert
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01
queryFrequency: 1h
status: Available
suppressionDuration: 5h
version: 1.0.0
severity: High
relevantTechniques:
- T1505
- T1562
name: Pathlock TDnR - ABAP Source Code Changes
kind: Scheduled
tactics:
- Persistence
- DefenseEvasion
requiredDataConnectors:
- dataTypes:
  - Pathlock_TDnR_CL
  connectorId: Pathlock_TDnR
description: Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml
triggerOperator: gt
triggerThreshold: 0
queryPeriod: 1h
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01')]",
      "properties": {
        "alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01",
        "customDetails": null,
        "description": "Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.",
        "displayName": "Pathlock TDnR - ABAP Source Code Changes",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "Bname",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByAlertDetails": [],
            "groupByCustomDetails": [],
            "groupByEntities": [],
            "lookbackDuration": "PT5H",
            "matchingMethod": "AnyAlert",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_ABAP_CHANGES.yaml",
        "query": "Pathlock_TDnR_CL\n| where DataSource == \"ABAP_CHANGES\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion",
          "Persistence"
        ],
        "techniques": [
          "T1505",
          "T1562"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}