Analytic rule catalog
Pathlock TDnR - Function Module Tested in Production
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c25 |
| Rulename | Pathlock TDnR - Function Module Tested in Production |
| Description | Detects execution of SAP function modules in a test environment context within production systems, forwarded by Pathlock Threat Detection and Response. This activity may indicate unauthorized code execution, exploitation of function module interfaces, or abuse of debugging capabilities. |
| Severity | High |
| Tactics | Execution |
| Techniques | T1059 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_FUNCTION_MODULE_TEST.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c25.json |
Pathlock_TDnR_CL
| where DataSource == "FUNCTION_MODULE_TEST"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
incidentConfiguration:
createIncident: true
groupingConfiguration:
groupByEntities: []
enabled: true
matchingMethod: AnyAlert
groupByCustomDetails: []
reopenClosedIncident: false
lookbackDuration: 5h
groupByAlertDetails: []
entityMappings:
- entityType: Account
fieldMappings:
- columnName: Bname
identifier: Name
- entityType: Host
fieldMappings:
- columnName: Hostname
identifier: HostName
- entityType: IP
fieldMappings:
- columnName: SrcIp
identifier: Address
query: |
Pathlock_TDnR_CL
| where DataSource == "FUNCTION_MODULE_TEST"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
suppressionEnabled: false
eventGroupingSettings:
aggregationKind: SingleAlert
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c25
queryFrequency: 1h
status: Available
suppressionDuration: 5h
version: 1.0.0
severity: High
relevantTechniques:
- T1059
name: Pathlock TDnR - Function Module Tested in Production
kind: Scheduled
tactics:
- Execution
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
description: Detects execution of SAP function modules in a test environment context within production systems, forwarded by Pathlock Threat Detection and Response. This activity may indicate unauthorized code execution, exploitation of function module interfaces, or abuse of debugging capabilities.
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_FUNCTION_MODULE_TEST.yaml
triggerOperator: gt
triggerThreshold: 0
queryPeriod: 1h
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c25')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c25')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c25",
"customDetails": null,
"description": "Detects execution of SAP function modules in a test environment context within production systems, forwarded by Pathlock Threat Detection and Response. This activity may indicate unauthorized code execution, exploitation of function module interfaces, or abuse of debugging capabilities.",
"displayName": "Pathlock TDnR - Function Module Tested in Production",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_FUNCTION_MODULE_TEST.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"FUNCTION_MODULE_TEST\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"Execution"
],
"techniques": [
"T1059"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}