Back
Id2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c73
RulenamePathlock TDnR - Multiple Login Sessions Detected
DescriptionDetects events from SAP multiple login monitoring (Table USR41), forwarded by Pathlock Threat Detection and Response. Multiple concurrent sessions from different sources may indicate credential sharing, session hijacking, or compromised accounts being used simultaneously by an attacker and the legitimate user.
SeverityMedium
TacticsInitialAccess
Discovery
CredentialAccess
TechniquesT1078
T1110
Required data connectorsPathlock_TDnR
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_USER_LOGINS.yaml
Version1.0.0
Arm template2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c73.json
Deploy To Azure
Pathlock_TDnR_CL
| where DataSource == "USER_LOGINS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
suppressionDuration: 5h
severity: Medium
tactics:
- InitialAccess
- Discovery
- CredentialAccess
queryFrequency: 1h
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c73
query: |
  Pathlock_TDnR_CL
  | where DataSource == "USER_LOGINS"
  | project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
            Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
            MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: Bname
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: Hostname
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: SrcIp
  entityType: IP
incidentConfiguration:
  groupingConfiguration:
    enabled: true
    groupByCustomDetails: []
    lookbackDuration: 5h
    reopenClosedIncident: false
    groupByEntities: []
    matchingMethod: AnyAlert
    groupByAlertDetails: []
  createIncident: true
kind: Scheduled
triggerOperator: gt
name: Pathlock TDnR - Multiple Login Sessions Detected
version: 1.0.0
status: Available
requiredDataConnectors:
- dataTypes:
  - Pathlock_TDnR_CL
  connectorId: Pathlock_TDnR
description: Detects events from SAP multiple login monitoring (Table USR41), forwarded by Pathlock Threat Detection and Response. Multiple concurrent sessions from different sources may indicate credential sharing, session hijacking, or compromised accounts being used simultaneously by an attacker and the legitimate user.
relevantTechniques:
- T1078
- T1110
queryPeriod: 1h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_USER_LOGINS.yaml
triggerThreshold: 0
suppressionEnabled: false
eventGroupingSettings:
  aggregationKind: SingleAlert
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c73')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c73')]",
      "properties": {
        "alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c73",
        "customDetails": null,
        "description": "Detects events from SAP multiple login monitoring (Table USR41), forwarded by Pathlock Threat Detection and Response. Multiple concurrent sessions from different sources may indicate credential sharing, session hijacking, or compromised accounts being used simultaneously by an attacker and the legitimate user.",
        "displayName": "Pathlock TDnR - Multiple Login Sessions Detected",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "Bname",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Hostname",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SrcIp",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByAlertDetails": [],
            "groupByCustomDetails": [],
            "groupByEntities": [],
            "lookbackDuration": "PT5H",
            "matchingMethod": "AnyAlert",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_USER_LOGINS.yaml",
        "query": "Pathlock_TDnR_CL\n| where DataSource == \"USER_LOGINS\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "CredentialAccess",
          "Discovery",
          "InitialAccess"
        ],
        "techniques": [
          "T1078",
          "T1110"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}