Analytic rule catalog
Pathlock TDnR - Database Cockpit Audit Events
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c23 |
| Rulename | Pathlock TDnR - Database Cockpit Audit Events |
| Description | Detects security-relevant events from the SAP Database Administration Cockpit (DBACOCKPIT), forwarded by Pathlock Threat Detection and Response. Suspicious DBACOCKPIT activity may indicate unauthorized direct database access, privilege escalation, or attempts to bypass SAP application controls. |
| Severity | Medium |
| Tactics | Discovery PrivilegeEscalation |
| Techniques | T1082 T1548 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_DBACOCKPIT.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c23.json |
Pathlock_TDnR_CL
| where DataSource == "DBACOCKPIT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
relevantTechniques:
- T1082
- T1548
triggerThreshold: 0
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c23
eventGroupingSettings:
aggregationKind: SingleAlert
queryPeriod: 1h
triggerOperator: gt
incidentConfiguration:
createIncident: true
groupingConfiguration:
enabled: true
reopenClosedIncident: false
groupByAlertDetails: []
matchingMethod: AnyAlert
groupByCustomDetails: []
groupByEntities: []
lookbackDuration: 5h
status: Available
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_DBACOCKPIT.yaml
queryFrequency: 1h
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
version: 1.0.0
tactics:
- Discovery
- PrivilegeEscalation
query: |
Pathlock_TDnR_CL
| where DataSource == "DBACOCKPIT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
name: Pathlock TDnR - Database Cockpit Audit Events
severity: Medium
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
suppressionDuration: 5h
suppressionEnabled: false
description: Detects security-relevant events from the SAP Database Administration Cockpit (DBACOCKPIT), forwarded by Pathlock Threat Detection and Response. Suspicious DBACOCKPIT activity may indicate unauthorized direct database access, privilege escalation, or attempts to bypass SAP application controls.
kind: Scheduled
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c23')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c23')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c23",
"customDetails": null,
"description": "Detects security-relevant events from the SAP Database Administration Cockpit (DBACOCKPIT), forwarded by Pathlock Threat Detection and Response. Suspicious DBACOCKPIT activity may indicate unauthorized direct database access, privilege escalation, or attempts to bypass SAP application controls.",
"displayName": "Pathlock TDnR - Database Cockpit Audit Events",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_DBACOCKPIT.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"DBACOCKPIT\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"Discovery",
"PrivilegeEscalation"
],
"techniques": [
"T1082",
"T1548"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}