Analytic rule catalog
Pathlock TDnR - Kerberos Keytab Changes
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12 |
| Rulename | Pathlock TDnR - Kerberos Keytab Changes |
| Description | Detects changes to Kerberos keytab configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to Kerberos settings may indicate credential theft, SSO bypass attempts, or persistent access mechanisms leveraging Kerberos delegation. |
| Severity | High |
| Tactics | CredentialAccess Persistence |
| Techniques | T1558 T1098 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_CHANGEDOC_KERBEROS.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12.json |
Pathlock_TDnR_CL
| where DataSource == "CHANGEDOC_KERBEROS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12
severity: High
queryPeriod: 1h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_CHANGEDOC_KERBEROS.yaml
eventGroupingSettings:
aggregationKind: SingleAlert
kind: Scheduled
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
triggerThreshold: 0
status: Available
relevantTechniques:
- T1558
- T1098
entityMappings:
- fieldMappings:
- columnName: Bname
identifier: Name
entityType: Account
- fieldMappings:
- columnName: Hostname
identifier: HostName
entityType: Host
- fieldMappings:
- columnName: SrcIp
identifier: Address
entityType: IP
suppressionDuration: 5h
suppressionEnabled: false
name: Pathlock TDnR - Kerberos Keytab Changes
query: |
Pathlock_TDnR_CL
| where DataSource == "CHANGEDOC_KERBEROS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
queryFrequency: 1h
version: 1.0.0
description: Detects changes to Kerberos keytab configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to Kerberos settings may indicate credential theft, SSO bypass attempts, or persistent access mechanisms leveraging Kerberos delegation.
tactics:
- CredentialAccess
- Persistence
triggerOperator: gt
incidentConfiguration:
createIncident: true
groupingConfiguration:
enabled: true
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5h
groupByCustomDetails: []
groupByEntities: []
groupByAlertDetails: []
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12",
"customDetails": null,
"description": "Detects changes to Kerberos keytab configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to Kerberos settings may indicate credential theft, SSO bypass attempts, or persistent access mechanisms leveraging Kerberos delegation.",
"displayName": "Pathlock TDnR - Kerberos Keytab Changes",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_CHANGEDOC_KERBEROS.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"CHANGEDOC_KERBEROS\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"CredentialAccess",
"Persistence"
],
"techniques": [
"T1098",
"T1558"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}