Pathlock TDnR - OData Application Log Events
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c59 |
| Rulename | Pathlock TDnR - OData Application Log Events |
| Description | Detects security events from SAP OData service application logs (SLG1), forwarded by Pathlock Threat Detection and Response. OData anomalies may indicate API abuse, unauthorized mass data extraction via OData endpoints, or exploitation of SAP Fiori and S/4HANA OData services. |
| Severity | Medium |
| Tactics | Collection Exfiltration |
| Techniques | T1213 T1048 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_SLG1_ODATA.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c59.json |
Pathlock_TDnR_CL
| where DataSource == "SLG1_ODATA"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
queryPeriod: 1h
suppressionDuration: 5h
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
eventGroupingSettings:
aggregationKind: SingleAlert
tactics:
- Collection
- Exfiltration
status: Available
relevantTechniques:
- T1213
- T1048
triggerOperator: gt
suppressionEnabled: false
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
queryFrequency: 1h
severity: Medium
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
groupByEntities: []
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5h
createIncident: true
triggerThreshold: 0
query: |
Pathlock_TDnR_CL
| where DataSource == "SLG1_ODATA"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
description: Detects security events from SAP OData service application logs (SLG1), forwarded by Pathlock Threat Detection and Response. OData anomalies may indicate API abuse, unauthorized mass data extraction via OData endpoints, or exploitation of SAP Fiori and S/4HANA OData services.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c59
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_SLG1_ODATA.yaml
name: Pathlock TDnR - OData Application Log Events