Analytic rule catalog
Pathlock TDnR - Switchable Authorization Runtime Changes
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c48 |
| Rulename | Pathlock TDnR - Switchable Authorization Runtime Changes |
| Description | Detects runtime changes to Switchable Authorizations (SACF) in SAP, forwarded by Pathlock Threat Detection and Response. Runtime SACF modifications take immediate effect and can instantly disable authorization checks in production, representing a critical real-time security control bypass. |
| Severity | High |
| Tactics | DefenseEvasion PrivilegeEscalation |
| Techniques | T1562 T1548 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SACF_CHANGES_RUNTIME.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c48.json |
Pathlock_TDnR_CL
| where DataSource == "SACF_CHANGES_RUNTIME"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
tactics:
- DefenseEvasion
- PrivilegeEscalation
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
incidentConfiguration:
createIncident: true
groupingConfiguration:
groupByAlertDetails: []
groupByEntities: []
matchingMethod: AnyAlert
groupByCustomDetails: []
enabled: true
reopenClosedIncident: false
lookbackDuration: 5h
queryPeriod: 1h
severity: High
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SACF_CHANGES_RUNTIME.yaml
queryFrequency: 1h
kind: Scheduled
description: Detects runtime changes to Switchable Authorizations (SACF) in SAP, forwarded by Pathlock Threat Detection and Response. Runtime SACF modifications take immediate effect and can instantly disable authorization checks in production, representing a critical real-time security control bypass.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c48
triggerOperator: gt
status: Available
relevantTechniques:
- T1562
- T1548
suppressionDuration: 5h
version: 1.0.0
triggerThreshold: 0
suppressionEnabled: false
name: Pathlock TDnR - Switchable Authorization Runtime Changes
eventGroupingSettings:
aggregationKind: SingleAlert
entityMappings:
- entityType: Account
fieldMappings:
- columnName: Bname
identifier: Name
- entityType: Host
fieldMappings:
- columnName: Hostname
identifier: HostName
- entityType: IP
fieldMappings:
- columnName: SrcIp
identifier: Address
query: |
Pathlock_TDnR_CL
| where DataSource == "SACF_CHANGES_RUNTIME"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c48')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c48')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c48",
"customDetails": null,
"description": "Detects runtime changes to Switchable Authorizations (SACF) in SAP, forwarded by Pathlock Threat Detection and Response. Runtime SACF modifications take immediate effect and can instantly disable authorization checks in production, representing a critical real-time security control bypass.",
"displayName": "Pathlock TDnR - Switchable Authorization Runtime Changes",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SACF_CHANGES_RUNTIME.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"SACF_CHANGES_RUNTIME\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"DefenseEvasion",
"PrivilegeEscalation"
],
"techniques": [
"T1548",
"T1562"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}