Analytic rule catalog
Pathlock TDnR - SAP HANA Database Audit Trail
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27 |
| Rulename | Pathlock TDnR - SAP HANA Database Audit Trail |
| Description | Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database. |
| Severity | Medium |
| Tactics | Discovery CredentialAccess InitialAccess |
| Techniques | T1082 T1078 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27.json |
Pathlock_TDnR_CL
| where DataSource == "HANA_AUDIT_TRAIL"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
kind: Scheduled
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml
version: 1.0.0
status: Available
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
relevantTechniques:
- T1082
- T1078
incidentConfiguration:
groupingConfiguration:
lookbackDuration: 5h
matchingMethod: AnyAlert
reopenClosedIncident: false
groupByEntities: []
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
createIncident: true
suppressionEnabled: false
query: |
Pathlock_TDnR_CL
| where DataSource == "HANA_AUDIT_TRAIL"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
tactics:
- Discovery
- CredentialAccess
- InitialAccess
queryFrequency: 1h
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27
triggerThreshold: 0
triggerOperator: gt
name: Pathlock TDnR - SAP HANA Database Audit Trail
queryPeriod: 1h
severity: Medium
entityMappings:
- fieldMappings:
- columnName: Bname
identifier: Name
entityType: Account
- fieldMappings:
- columnName: Hostname
identifier: HostName
entityType: Host
- fieldMappings:
- columnName: SrcIp
identifier: Address
entityType: IP
suppressionDuration: 5h
eventGroupingSettings:
aggregationKind: SingleAlert
description: Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database.
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27",
"customDetails": null,
"description": "Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database.",
"displayName": "Pathlock TDnR - SAP HANA Database Audit Trail",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"HANA_AUDIT_TRAIL\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"CredentialAccess",
"Discovery",
"InitialAccess"
],
"techniques": [
"T1078",
"T1082"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}