Analytic rule catalog
Pathlock TDnR - SAP HANA Database Audit Trail
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27 |
| Rulename | Pathlock TDnR - SAP HANA Database Audit Trail |
| Description | Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database. |
| Severity | Medium |
| Tactics | Discovery CredentialAccess InitialAccess |
| Techniques | T1082 T1078 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27.json |
Pathlock_TDnR_CL
| where DataSource == "HANA_AUDIT_TRAIL"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
suppressionDuration: 5h
severity: Medium
tactics:
- Discovery
- CredentialAccess
- InitialAccess
queryFrequency: 1h
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27
query: |
Pathlock_TDnR_CL
| where DataSource == "HANA_AUDIT_TRAIL"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Bname
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
- fieldMappings:
- identifier: Address
columnName: SrcIp
entityType: IP
incidentConfiguration:
groupingConfiguration:
enabled: true
groupByCustomDetails: []
lookbackDuration: 5h
reopenClosedIncident: false
groupByEntities: []
matchingMethod: AnyAlert
groupByAlertDetails: []
createIncident: true
kind: Scheduled
triggerOperator: gt
name: Pathlock TDnR - SAP HANA Database Audit Trail
version: 1.0.0
status: Available
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
description: Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database.
relevantTechniques:
- T1082
- T1078
queryPeriod: 1h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml
triggerThreshold: 0
suppressionEnabled: false
eventGroupingSettings:
aggregationKind: SingleAlert
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27",
"customDetails": null,
"description": "Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database.",
"displayName": "Pathlock TDnR - SAP HANA Database Audit Trail",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"HANA_AUDIT_TRAIL\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"CredentialAccess",
"Discovery",
"InitialAccess"
],
"techniques": [
"T1078",
"T1082"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}