Back
Id2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58
RulenamePathlock TDnR - LDAP Synchronization Application Log Events
DescriptionDetects security events from the SAP LDAP synchronization application log (SLG1), forwarded by Pathlock Threat Detection and Response. LDAP sync anomalies may indicate unauthorized identity directory manipulation, credential harvesting via LDAP queries, or synchronization abuse to propagate unauthorized access.
SeverityMedium
TacticsCredentialAccess
TechniquesT1552
Required data connectorsPathlock_TDnR
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SLG1_LDAPSYNC.yaml
Version1.0.0
Arm template2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58.json
Deploy To Azure
Pathlock_TDnR_CL
| where DataSource == "SLG1_LDAPSYNC"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
suppressionDuration: 5h
severity: Medium
tactics:
- CredentialAccess
queryFrequency: 1h
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58
query: |
  Pathlock_TDnR_CL
  | where DataSource == "SLG1_LDAPSYNC"
  | project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
            Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
            MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: Bname
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: Hostname
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: SrcIp
  entityType: IP
incidentConfiguration:
  groupingConfiguration:
    enabled: true
    groupByCustomDetails: []
    lookbackDuration: 5h
    reopenClosedIncident: false
    groupByEntities: []
    matchingMethod: AnyAlert
    groupByAlertDetails: []
  createIncident: true
kind: Scheduled
triggerOperator: gt
name: Pathlock TDnR - LDAP Synchronization Application Log Events
version: 1.0.0
status: Available
requiredDataConnectors:
- dataTypes:
  - Pathlock_TDnR_CL
  connectorId: Pathlock_TDnR
description: Detects security events from the SAP LDAP synchronization application log (SLG1), forwarded by Pathlock Threat Detection and Response. LDAP sync anomalies may indicate unauthorized identity directory manipulation, credential harvesting via LDAP queries, or synchronization abuse to propagate unauthorized access.
relevantTechniques:
- T1552
queryPeriod: 1h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SLG1_LDAPSYNC.yaml
triggerThreshold: 0
suppressionEnabled: false
eventGroupingSettings:
  aggregationKind: SingleAlert
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58')]",
      "properties": {
        "alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58",
        "customDetails": null,
        "description": "Detects security events from the SAP LDAP synchronization application log (SLG1), forwarded by Pathlock Threat Detection and Response. LDAP sync anomalies may indicate unauthorized identity directory manipulation, credential harvesting via LDAP queries, or synchronization abuse to propagate unauthorized access.",
        "displayName": "Pathlock TDnR - LDAP Synchronization Application Log Events",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "Bname",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByAlertDetails": [],
            "groupByCustomDetails": [],
            "groupByEntities": [],
            "lookbackDuration": "PT5H",
            "matchingMethod": "AnyAlert",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SLG1_LDAPSYNC.yaml",
        "query": "Pathlock_TDnR_CL\n| where DataSource == \"SLG1_LDAPSYNC\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "CredentialAccess"
        ],
        "techniques": [
          "T1552"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}