Pathlock TDnR - Emergency User AdminTrack Activity
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c50 |
| Rulename | Pathlock TDnR - Emergency User (AdminTrack) Activity |
| Description | Detects activity from emergency user accounts tracked by Pathlock AdminTrack in SAP, forwarded by Pathlock Threat Detection and Response. Emergency user (firefighter) account usage should always be reviewed as these accounts carry broad privileges and any unauthorized or unreviewed use may indicate insider threat or account takeover. |
| Severity | High |
| Tactics | Persistence PrivilegeEscalation |
| Techniques | T1078 T1548 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_SAST_AT.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c50.json |
Pathlock_TDnR_CL
| where DataSource == "SAST_AT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
queryPeriod: 1h
suppressionDuration: 5h
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
eventGroupingSettings:
aggregationKind: SingleAlert
tactics:
- Persistence
- PrivilegeEscalation
status: Available
relevantTechniques:
- T1078
- T1548
triggerOperator: gt
suppressionEnabled: false
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
queryFrequency: 1h
severity: High
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
groupByEntities: []
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5h
createIncident: true
triggerThreshold: 0
query: |
Pathlock_TDnR_CL
| where DataSource == "SAST_AT"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
description: Detects activity from emergency user accounts tracked by Pathlock AdminTrack in SAP, forwarded by Pathlock Threat Detection and Response. Emergency user (firefighter) account usage should always be reviewed as these accounts carry broad privileges and any unauthorized or unreviewed use may indicate insider threat or account takeover.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c50
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_SAST_AT.yaml
name: Pathlock TDnR - Emergency User (AdminTrack) Activity