Back
Id2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12
RulenamePathlock TDnR - Kerberos Keytab Changes
DescriptionDetects changes to Kerberos keytab configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to Kerberos settings may indicate credential theft, SSO bypass attempts, or persistent access mechanisms leveraging Kerberos delegation.
SeverityHigh
TacticsCredentialAccess
Persistence
TechniquesT1558
T1098
Required data connectorsPathlock_TDnR
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_CHANGEDOC_KERBEROS.yaml
Version1.0.0
Arm template2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12.json
Deploy To Azure
Pathlock_TDnR_CL
| where DataSource == "CHANGEDOC_KERBEROS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
tactics:
- CredentialAccess
- Persistence
name: Pathlock TDnR - Kerberos Keytab Changes
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_CHANGEDOC_KERBEROS.yaml
version: 1.0.0
queryFrequency: 1h
requiredDataConnectors:
- connectorId: Pathlock_TDnR
  dataTypes:
  - Pathlock_TDnR_CL
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12
triggerThreshold: 0
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: Bname
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: Hostname
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: SrcIp
  entityType: IP
queryPeriod: 1h
severity: High
relevantTechniques:
- T1558
- T1098
eventGroupingSettings:
  aggregationKind: SingleAlert
suppressionEnabled: false
description: Detects changes to Kerberos keytab configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to Kerberos settings may indicate credential theft, SSO bypass attempts, or persistent access mechanisms leveraging Kerberos delegation.
triggerOperator: gt
suppressionDuration: 5h
status: Available
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    enabled: true
    groupByCustomDetails: []
    groupByAlertDetails: []
    matchingMethod: AnyAlert
    lookbackDuration: 5h
    reopenClosedIncident: false
    groupByEntities: []
kind: Scheduled
query: |
  Pathlock_TDnR_CL
  | where DataSource == "CHANGEDOC_KERBEROS"
  | project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
            Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
            MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12')]",
      "properties": {
        "alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12",
        "customDetails": null,
        "description": "Detects changes to Kerberos keytab configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to Kerberos settings may indicate credential theft, SSO bypass attempts, or persistent access mechanisms leveraging Kerberos delegation.",
        "displayName": "Pathlock TDnR - Kerberos Keytab Changes",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "Bname",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByAlertDetails": [],
            "groupByCustomDetails": [],
            "groupByEntities": [],
            "lookbackDuration": "PT5H",
            "matchingMethod": "AnyAlert",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_CHANGEDOC_KERBEROS.yaml",
        "query": "Pathlock_TDnR_CL\n| where DataSource == \"CHANGEDOC_KERBEROS\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "CredentialAccess",
          "Persistence"
        ],
        "techniques": [
          "T1098",
          "T1558"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}