Analytic rule catalog
Pathlock TDnR - User-Role Assignment Changes
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c76 |
| Rulename | Pathlock TDnR - User-Role Assignment Changes |
| Description | Detects changes to user-to-role assignments in SAP (SU01 roles tab), forwarded by Pathlock Threat Detection and Response. Unauthorized role assignments are the primary mechanism for granting and revoking SAP access, and unexpected changes may indicate privilege escalation, account backdooring, or unauthorized access provisioning. |
| Severity | High |
| Tactics | PrivilegeEscalation Persistence |
| Techniques | T1548 T1098 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_USER_ROLES.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c76.json |
Pathlock_TDnR_CL
| where DataSource == "USER_ROLES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
incidentConfiguration:
groupingConfiguration:
groupByAlertDetails: []
groupByCustomDetails: []
lookbackDuration: 5h
enabled: true
reopenClosedIncident: false
matchingMethod: AnyAlert
groupByEntities: []
createIncident: true
name: Pathlock TDnR - User-Role Assignment Changes
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: Detects changes to user-to-role assignments in SAP (SU01 roles tab), forwarded by Pathlock Threat Detection and Response. Unauthorized role assignments are the primary mechanism for granting and revoking SAP access, and unexpected changes may indicate privilege escalation, account backdooring, or unauthorized access provisioning.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c76
triggerThreshold: 0
queryPeriod: 1h
query: |
Pathlock_TDnR_CL
| where DataSource == "USER_ROLES"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
status: Available
eventGroupingSettings:
aggregationKind: SingleAlert
severity: High
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_USER_ROLES.yaml
relevantTechniques:
- T1548
- T1098
tactics:
- PrivilegeEscalation
- Persistence
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Bname
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
- fieldMappings:
- identifier: Address
columnName: SrcIp
entityType: IP
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c76')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c76')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c76",
"customDetails": null,
"description": "Detects changes to user-to-role assignments in SAP (SU01 roles tab), forwarded by Pathlock Threat Detection and Response. Unauthorized role assignments are the primary mechanism for granting and revoking SAP access, and unexpected changes may indicate privilege escalation, account backdooring, or unauthorized access provisioning.",
"displayName": "Pathlock TDnR - User-Role Assignment Changes",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_USER_ROLES.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"USER_ROLES\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "High",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"Persistence",
"PrivilegeEscalation"
],
"techniques": [
"T1098",
"T1548"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}