Pathlock TDnR - SAP HANA Database Audit Trail
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27 |
| Rulename | Pathlock TDnR - SAP HANA Database Audit Trail |
| Description | Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database. |
| Severity | Medium |
| Tactics | Discovery CredentialAccess InitialAccess |
| Techniques | T1082 T1078 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27.json |
Pathlock_TDnR_CL
| where DataSource == "HANA_AUDIT_TRAIL"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
queryPeriod: 1h
suppressionDuration: 5h
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
eventGroupingSettings:
aggregationKind: SingleAlert
tactics:
- Discovery
- CredentialAccess
- InitialAccess
status: Available
relevantTechniques:
- T1082
- T1078
triggerOperator: gt
suppressionEnabled: false
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
queryFrequency: 1h
severity: Medium
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
groupByEntities: []
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5h
createIncident: true
triggerThreshold: 0
query: |
Pathlock_TDnR_CL
| where DataSource == "HANA_AUDIT_TRAIL"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
description: Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml
name: Pathlock TDnR - SAP HANA Database Audit Trail