Analytic rule catalog
Pathlock TDnR - SAP Web Dispatcher HTTP Events
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77 |
| Rulename | Pathlock TDnR - SAP Web Dispatcher HTTP Events |
| Description | Detects security-relevant events from SAP Web Dispatcher HTTP logs, forwarded by Pathlock Threat Detection and Response. Web Dispatcher anomalies may indicate web application attacks, request smuggling, unauthorized access to backend SAP systems, or exploitation of SAP Fiori and S/4HANA web frontends. |
| Severity | Medium |
| Tactics | InitialAccess CommandAndControl |
| Techniques | T1190 T1071 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_WD_HTTP_LOG.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77.json |
Pathlock_TDnR_CL
| where DataSource == "WD_HTTP_LOG"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
entityMappings:
- entityType: Account
fieldMappings:
- identifier: Name
columnName: Bname
- entityType: Host
fieldMappings:
- identifier: HostName
columnName: Hostname
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SrcIp
name: Pathlock TDnR - SAP Web Dispatcher HTTP Events
queryFrequency: 1h
triggerOperator: gt
status: Available
suppressionDuration: 5h
queryPeriod: 1h
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
tactics:
- InitialAccess
- CommandAndControl
query: |
Pathlock_TDnR_CL
| where DataSource == "WD_HTTP_LOG"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
description: Detects security-relevant events from SAP Web Dispatcher HTTP logs, forwarded by Pathlock Threat Detection and Response. Web Dispatcher anomalies may indicate web application attacks, request smuggling, unauthorized access to backend SAP systems, or exploitation of SAP Fiori and S/4HANA web frontends.
severity: Medium
incidentConfiguration:
groupingConfiguration:
lookbackDuration: 5h
groupByCustomDetails: []
groupByEntities: []
enabled: true
groupByAlertDetails: []
matchingMethod: AnyAlert
reopenClosedIncident: false
createIncident: true
kind: Scheduled
eventGroupingSettings:
aggregationKind: SingleAlert
suppressionEnabled: false
triggerThreshold: 0
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_WD_HTTP_LOG.yaml
version: 1.0.0
relevantTechniques:
- T1190
- T1071
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77",
"customDetails": null,
"description": "Detects security-relevant events from SAP Web Dispatcher HTTP logs, forwarded by Pathlock Threat Detection and Response. Web Dispatcher anomalies may indicate web application attacks, request smuggling, unauthorized access to backend SAP systems, or exploitation of SAP Fiori and S/4HANA web frontends.",
"displayName": "Pathlock TDnR - SAP Web Dispatcher HTTP Events",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_WD_HTTP_LOG.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"WD_HTTP_LOG\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl",
"InitialAccess"
],
"techniques": [
"T1071",
"T1190"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}