Pathlock TDnR - SAP Cloud Account Administration Events
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c21 |
| Rulename | Pathlock TDnR - SAP Cloud Account Administration Events |
| Description | Detects account administration events in SAP Cloud environments, forwarded by Pathlock Threat Detection and Response. Suspicious cloud account activities may indicate unauthorized provisioning, privilege escalation, or account takeover in SAP cloud tenants. |
| Severity | Medium |
| Tactics | InitialAccess Persistence |
| Techniques | T1078 T1136 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_CLOUD_ACCOUNT_LOGS.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c21.json |
Pathlock_TDnR_CL
| where DataSource == "CLOUD_ACCOUNT_LOGS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
queryPeriod: 1h
suppressionDuration: 5h
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
eventGroupingSettings:
aggregationKind: SingleAlert
tactics:
- InitialAccess
- Persistence
status: Available
relevantTechniques:
- T1078
- T1136
triggerOperator: gt
suppressionEnabled: false
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
queryFrequency: 1h
severity: Medium
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
groupByEntities: []
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5h
createIncident: true
triggerThreshold: 0
query: |
Pathlock_TDnR_CL
| where DataSource == "CLOUD_ACCOUNT_LOGS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
description: Detects account administration events in SAP Cloud environments, forwarded by Pathlock Threat Detection and Response. Suspicious cloud account activities may indicate unauthorized provisioning, privilege escalation, or account takeover in SAP cloud tenants.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c21
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_CLOUD_ACCOUNT_LOGS.yaml
name: Pathlock TDnR - SAP Cloud Account Administration Events