Analytic rule catalog
Pathlock TDnR - SAP Batch Job Events
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c04 |
| Rulename | Pathlock TDnR - SAP Batch Job Events |
| Description | Detects security-relevant SAP batch processing events, forwarded by Pathlock Threat Detection and Response. Malicious or unauthorized batch jobs may be used to execute code, exfiltrate data, or establish persistent tasks within the SAP environment. |
| Severity | Medium |
| Tactics | Execution Persistence |
| Techniques | T1053 T1059 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_BATCH_JOBS.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c04.json |
Pathlock_TDnR_CL
| where DataSource == "BATCH_JOBS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
incidentConfiguration:
groupingConfiguration:
groupByAlertDetails: []
groupByCustomDetails: []
lookbackDuration: 5h
enabled: true
reopenClosedIncident: false
matchingMethod: AnyAlert
groupByEntities: []
createIncident: true
name: Pathlock TDnR - SAP Batch Job Events
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: Detects security-relevant SAP batch processing events, forwarded by Pathlock Threat Detection and Response. Malicious or unauthorized batch jobs may be used to execute code, exfiltrate data, or establish persistent tasks within the SAP environment.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c04
triggerThreshold: 0
queryPeriod: 1h
query: |
Pathlock_TDnR_CL
| where DataSource == "BATCH_JOBS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
status: Available
eventGroupingSettings:
aggregationKind: SingleAlert
severity: Medium
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_BATCH_JOBS.yaml
relevantTechniques:
- T1053
- T1059
tactics:
- Execution
- Persistence
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Bname
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
- fieldMappings:
- identifier: Address
columnName: SrcIp
entityType: IP
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c04')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c04')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c04",
"customDetails": null,
"description": "Detects security-relevant SAP batch processing events, forwarded by Pathlock Threat Detection and Response. Malicious or unauthorized batch jobs may be used to execute code, exfiltrate data, or establish persistent tasks within the SAP environment.",
"displayName": "Pathlock TDnR - SAP Batch Job Events",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_BATCH_JOBS.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"BATCH_JOBS\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"Execution",
"Persistence"
],
"techniques": [
"T1053",
"T1059"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}