Analytic rule catalog
Pathlock TDnR - SAP Router Log Events
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c49 |
| Rulename | Pathlock TDnR - SAP Router Log Events |
| Description | Detects security-relevant events from the SAP Router log, forwarded by Pathlock Threat Detection and Response. SAP Router events may reveal unauthorized external connections, suspicious routing patterns, or attempts to use the SAP Router as a pivot point for lateral movement. |
| Severity | Medium |
| Tactics | LateralMovement CommandAndControl |
| Techniques | T1021 T1572 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SAPROUTER.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c49.json |
Pathlock_TDnR_CL
| where DataSource == "SAPROUTER"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
severity: Medium
incidentConfiguration:
groupingConfiguration:
enabled: true
groupByAlertDetails: []
lookbackDuration: 5h
matchingMethod: AnyAlert
groupByCustomDetails: []
reopenClosedIncident: false
groupByEntities: []
createIncident: true
suppressionEnabled: false
relevantTechniques:
- T1021
- T1572
version: 1.0.0
triggerThreshold: 0
eventGroupingSettings:
aggregationKind: SingleAlert
status: Available
query: |
Pathlock_TDnR_CL
| where DataSource == "SAPROUTER"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
name: Pathlock TDnR - SAP Router Log Events
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
triggerOperator: gt
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
tactics:
- LateralMovement
- CommandAndControl
queryFrequency: 1h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SAPROUTER.yaml
kind: Scheduled
queryPeriod: 1h
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c49
suppressionDuration: 5h
description: Detects security-relevant events from the SAP Router log, forwarded by Pathlock Threat Detection and Response. SAP Router events may reveal unauthorized external connections, suspicious routing patterns, or attempts to use the SAP Router as a pivot point for lateral movement.
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c49')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c49')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c49",
"customDetails": null,
"description": "Detects security-relevant events from the SAP Router log, forwarded by Pathlock Threat Detection and Response. SAP Router events may reveal unauthorized external connections, suspicious routing patterns, or attempts to use the SAP Router as a pivot point for lateral movement.",
"displayName": "Pathlock TDnR - SAP Router Log Events",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SAPROUTER.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"SAPROUTER\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl",
"LateralMovement"
],
"techniques": [
"T1021",
"T1572"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}