Analytic rule catalog
Pathlock TDnR - Generic Table Content Changes
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67 |
| Rulename | Pathlock TDnR - Generic Table Content Changes |
| Description | Detects generic change documents for SAP table content, forwarded by Pathlock Threat Detection and Response. Direct table data modifications may bypass normal application validation and audit trails, and could indicate data manipulation, configuration tampering, or fraud concealment. |
| Severity | High |
| Tactics | DefenseEvasion Impact |
| Techniques | T1565 T1562 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_TABLE_CHANGES.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67.json |
Pathlock_TDnR_CL
| where DataSource == "TABLE_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
suppressionDuration: 5h
version: 1.0.0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_TABLE_CHANGES.yaml
triggerThreshold: 0
requiredDataConnectors:
- dataTypes:
- Pathlock_TDnR_CL
connectorId: Pathlock_TDnR
tactics:
- DefenseEvasion
- Impact
relevantTechniques:
- T1565
- T1562
kind: Scheduled
incidentConfiguration:
groupingConfiguration:
lookbackDuration: 5h
matchingMethod: AnyAlert
groupByCustomDetails: []
enabled: true
reopenClosedIncident: false
groupByAlertDetails: []
groupByEntities: []
createIncident: true
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Bname
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
- fieldMappings:
- identifier: Address
columnName: SrcIp
entityType: IP
description: Detects generic change documents for SAP table content, forwarded by Pathlock Threat Detection and Response. Direct table data modifications may bypass normal application validation and audit trails, and could indicate data manipulation, configuration tampering, or fraud concealment.
triggerOperator: gt
suppressionEnabled: false
status: Available
queryFrequency: 1h
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67
name: Pathlock TDnR - Generic Table Content Changes
severity: High
query: |
Pathlock_TDnR_CL
| where DataSource == "TABLE_CHANGES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
queryPeriod: 1h
eventGroupingSettings:
aggregationKind: SingleAlert
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67",
"customDetails": null,
"description": "Detects generic change documents for SAP table content, forwarded by Pathlock Threat Detection and Response. Direct table data modifications may bypass normal application validation and audit trails, and could indicate data manipulation, configuration tampering, or fraud concealment.",
"displayName": "Pathlock TDnR - Generic Table Content Changes",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_TABLE_CHANGES.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"TABLE_CHANGES\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"DefenseEvasion",
"Impact"
],
"techniques": [
"T1562",
"T1565"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}