Pathlock TDnR - RFC Connection Changes
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c45 |
| Rulename | Pathlock TDnR - RFC Connection Changes |
| Description | Detects changes to RFC (Remote Function Call) connection definitions in SAP (transaction SM59), forwarded by Pathlock Threat Detection and Response. Unauthorized RFC changes may introduce backdoor connections, redirect communications to malicious systems, or enable lateral movement across SAP landscapes. |
| Severity | High |
| Tactics | LateralMovement Persistence |
| Techniques | T1021 T1098 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_RFC_DESTINATIONS.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c45.json |
Pathlock_TDnR_CL
| where DataSource == "RFC_DESTINATIONS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
queryPeriod: 1h
suppressionDuration: 5h
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
eventGroupingSettings:
aggregationKind: SingleAlert
tactics:
- LateralMovement
- Persistence
status: Available
relevantTechniques:
- T1021
- T1098
triggerOperator: gt
suppressionEnabled: false
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
queryFrequency: 1h
severity: High
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
groupByEntities: []
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5h
createIncident: true
triggerThreshold: 0
query: |
Pathlock_TDnR_CL
| where DataSource == "RFC_DESTINATIONS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
description: Detects changes to RFC (Remote Function Call) connection definitions in SAP (transaction SM59), forwarded by Pathlock Threat Detection and Response. Unauthorized RFC changes may introduce backdoor connections, redirect communications to malicious systems, or enable lateral movement across SAP landscapes.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c45
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_RFC_DESTINATIONS.yaml
name: Pathlock TDnR - RFC Connection Changes