Pathlock TDnR - Generic Table Content Changes
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67 |
| Rulename | Pathlock TDnR - Generic Table Content Changes |
| Description | Detects generic change documents for SAP table content, forwarded by Pathlock Threat Detection and Response. Direct table data modifications may bypass normal application validation and audit trails, and could indicate data manipulation, configuration tampering, or fraud concealment. |
| Severity | High |
| Tactics | DefenseEvasion Impact |
| Techniques | T1565 T1562 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_TABLE_CHANGES.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67.json |
Pathlock_TDnR_CL
| where DataSource == "TABLE_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
queryPeriod: 1h
suppressionDuration: 5h
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
eventGroupingSettings:
aggregationKind: SingleAlert
tactics:
- DefenseEvasion
- Impact
status: Available
relevantTechniques:
- T1565
- T1562
triggerOperator: gt
suppressionEnabled: false
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
queryFrequency: 1h
severity: High
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
groupByEntities: []
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
reopenClosedIncident: false
matchingMethod: AnyAlert
lookbackDuration: 5h
createIncident: true
triggerThreshold: 0
query: |
Pathlock_TDnR_CL
| where DataSource == "TABLE_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
description: Detects generic change documents for SAP table content, forwarded by Pathlock Threat Detection and Response. Direct table data modifications may bypass normal application validation and audit trails, and could indicate data manipulation, configuration tampering, or fraud concealment.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic Rules/Pathlock_TDnR_TABLE_CHANGES.yaml
name: Pathlock TDnR - Generic Table Content Changes