Pathlock TDnR - SAP Security Audit Log Events
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c56 |
| Rulename | Pathlock TDnR - SAP Security Audit Log Events |
| Description | Detects security-relevant events from the SAP Security Audit Log (SM20), forwarded by Pathlock Threat Detection and Response. The Security Audit Log captures critical security events including failed logons, authorization failures, and restricted transactions - anomalies here are strong indicators of attack activity or insider threats. |
| Severity | High |
| Tactics | Discovery DefenseEvasion |
| Techniques | T1082 T1562 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_SECURITY_AUDIT_LOG.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c56.json |
Pathlock_TDnR_CL
| where DataSource == "SECURITY_AUDIT_LOG"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
tactics:
- Discovery
- DefenseEvasion
suppressionEnabled: false
suppressionDuration: 5h
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
incidentConfiguration:
groupingConfiguration:
reopenClosedIncident: false
groupByAlertDetails: []
lookbackDuration: 5h
groupByEntities: []
groupByCustomDetails: []
enabled: true
matchingMethod: AnyAlert
createIncident: true
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c56
severity: High
eventGroupingSettings:
aggregationKind: SingleAlert
status: Available
query: |
Pathlock_TDnR_CL
| where DataSource == "SECURITY_AUDIT_LOG"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_SECURITY_AUDIT_LOG.yaml
kind: Scheduled
queryPeriod: 1h
version: 1.0.0
name: Pathlock TDnR - SAP Security Audit Log Events
queryFrequency: 1h
triggerThreshold: 0
relevantTechniques:
- T1082
- T1562
description: Detects security-relevant events from the SAP Security Audit Log (SM20), forwarded by Pathlock Threat Detection and Response. The Security Audit Log captures critical security events including failed logons, authorization failures, and restricted transactions - anomalies here are strong indicators of attack activity or insider threats.
triggerOperator: gt