Back
Id2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58
RulenamePathlock TDnR - LDAP Synchronization Application Log Events
DescriptionDetects security events from the SAP LDAP synchronization application log (SLG1), forwarded by Pathlock Threat Detection and Response. LDAP sync anomalies may indicate unauthorized identity directory manipulation, credential harvesting via LDAP queries, or synchronization abuse to propagate unauthorized access.
SeverityMedium
TacticsCredentialAccess
TechniquesT1552
Required data connectorsPathlock_TDnR
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SLG1_LDAPSYNC.yaml
Version1.0.0
Arm template2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58.json
Deploy To Azure
Pathlock_TDnR_CL
| where DataSource == "SLG1_LDAPSYNC"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
tactics:
- CredentialAccess
name: Pathlock TDnR - LDAP Synchronization Application Log Events
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SLG1_LDAPSYNC.yaml
version: 1.0.0
queryFrequency: 1h
requiredDataConnectors:
- connectorId: Pathlock_TDnR
  dataTypes:
  - Pathlock_TDnR_CL
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58
triggerThreshold: 0
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: Bname
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: Hostname
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: SrcIp
  entityType: IP
queryPeriod: 1h
severity: Medium
relevantTechniques:
- T1552
eventGroupingSettings:
  aggregationKind: SingleAlert
suppressionEnabled: false
description: Detects security events from the SAP LDAP synchronization application log (SLG1), forwarded by Pathlock Threat Detection and Response. LDAP sync anomalies may indicate unauthorized identity directory manipulation, credential harvesting via LDAP queries, or synchronization abuse to propagate unauthorized access.
triggerOperator: gt
suppressionDuration: 5h
status: Available
incidentConfiguration:
  createIncident: true
  groupingConfiguration:
    enabled: true
    groupByCustomDetails: []
    groupByAlertDetails: []
    matchingMethod: AnyAlert
    lookbackDuration: 5h
    reopenClosedIncident: false
    groupByEntities: []
kind: Scheduled
query: |
  Pathlock_TDnR_CL
  | where DataSource == "SLG1_LDAPSYNC"
  | project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
            Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
            MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58')]",
      "properties": {
        "alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58",
        "customDetails": null,
        "description": "Detects security events from the SAP LDAP synchronization application log (SLG1), forwarded by Pathlock Threat Detection and Response. LDAP sync anomalies may indicate unauthorized identity directory manipulation, credential harvesting via LDAP queries, or synchronization abuse to propagate unauthorized access.",
        "displayName": "Pathlock TDnR - LDAP Synchronization Application Log Events",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "Bname",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByAlertDetails": [],
            "groupByCustomDetails": [],
            "groupByEntities": [],
            "lookbackDuration": "PT5H",
            "matchingMethod": "AnyAlert",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_SLG1_LDAPSYNC.yaml",
        "query": "Pathlock_TDnR_CL\n| where DataSource == \"SLG1_LDAPSYNC\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "CredentialAccess"
        ],
        "techniques": [
          "T1552"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}