Analytic rule catalog
Pathlock TDnR - HANA Standalone DB Connection Events
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c28 |
| Rulename | Pathlock TDnR - HANA Standalone DB Connection Events |
| Description | Detects security events from HANA standalone database connections via DBCON in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized DBCON connections allow direct database access and may be used for lateral movement or to bypass SAP application-layer controls. |
| Severity | Medium |
| Tactics | LateralMovement |
| Techniques | T1021 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_DBCON_CONNECT.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c28.json |
Pathlock_TDnR_CL
| where DataSource == "HANA_DBCON_CONNECT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
severity: Medium
incidentConfiguration:
groupingConfiguration:
enabled: true
groupByAlertDetails: []
lookbackDuration: 5h
matchingMethod: AnyAlert
groupByCustomDetails: []
reopenClosedIncident: false
groupByEntities: []
createIncident: true
suppressionEnabled: false
relevantTechniques:
- T1021
version: 1.0.0
triggerThreshold: 0
eventGroupingSettings:
aggregationKind: SingleAlert
status: Available
query: |
Pathlock_TDnR_CL
| where DataSource == "HANA_DBCON_CONNECT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
name: Pathlock TDnR - HANA Standalone DB Connection Events
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
triggerOperator: gt
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
tactics:
- LateralMovement
queryFrequency: 1h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_DBCON_CONNECT.yaml
kind: Scheduled
queryPeriod: 1h
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c28
suppressionDuration: 5h
description: Detects security events from HANA standalone database connections via DBCON in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized DBCON connections allow direct database access and may be used for lateral movement or to bypass SAP application-layer controls.
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c28')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c28')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c28",
"customDetails": null,
"description": "Detects security events from HANA standalone database connections via DBCON in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized DBCON connections allow direct database access and may be used for lateral movement or to bypass SAP application-layer controls.",
"displayName": "Pathlock TDnR - HANA Standalone DB Connection Events",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_HANA_DBCON_CONNECT.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"HANA_DBCON_CONNECT\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"LateralMovement"
],
"techniques": [
"T1021"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}