Pathlock TDnR - Critical File Integrity Changes
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c24 |
| Rulename | Pathlock TDnR - Critical File Integrity Changes |
| Description | Detects changes to checksums of critical SAP files, forwarded by Pathlock Threat Detection and Response. File integrity violations may indicate malware installation, unauthorized patching, or tampering with SAP executables and configuration files. |
| Severity | High |
| Tactics | DefenseEvasion Persistence |
| Techniques | T1562 T1036 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_FILE_CHECKSUM.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c24.json |
Pathlock_TDnR_CL
| where DataSource == "FILE_CHECKSUM"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
tactics:
- DefenseEvasion
- Persistence
suppressionEnabled: false
suppressionDuration: 5h
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
incidentConfiguration:
groupingConfiguration:
reopenClosedIncident: false
groupByAlertDetails: []
lookbackDuration: 5h
groupByEntities: []
groupByCustomDetails: []
enabled: true
matchingMethod: AnyAlert
createIncident: true
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c24
severity: High
eventGroupingSettings:
aggregationKind: SingleAlert
status: Available
query: |
Pathlock_TDnR_CL
| where DataSource == "FILE_CHECKSUM"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_FILE_CHECKSUM.yaml
kind: Scheduled
queryPeriod: 1h
version: 1.0.0
name: Pathlock TDnR - Critical File Integrity Changes
queryFrequency: 1h
triggerThreshold: 0
relevantTechniques:
- T1562
- T1036
description: Detects changes to checksums of critical SAP files, forwarded by Pathlock Threat Detection and Response. File integrity violations may indicate malware installation, unauthorized patching, or tampering with SAP executables and configuration files.
triggerOperator: gt