Analytic rule catalog
Pathlock TDnR - SAP Web Dispatcher HTTP Events
Back
| Id | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77 |
| Rulename | Pathlock TDnR - SAP Web Dispatcher HTTP Events |
| Description | Detects security-relevant events from SAP Web Dispatcher HTTP logs, forwarded by Pathlock Threat Detection and Response. Web Dispatcher anomalies may indicate web application attacks, request smuggling, unauthorized access to backend SAP systems, or exploitation of SAP Fiori and S/4HANA web frontends. |
| Severity | Medium |
| Tactics | InitialAccess CommandAndControl |
| Techniques | T1190 T1071 |
| Required data connectors | Pathlock_TDnR |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_WD_HTTP_LOG.yaml |
| Version | 1.0.0 |
| Arm template | 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77.json |
Pathlock_TDnR_CL
| where DataSource == "WD_HTTP_LOG"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
incidentConfiguration:
groupingConfiguration:
groupByAlertDetails: []
groupByCustomDetails: []
lookbackDuration: 5h
enabled: true
reopenClosedIncident: false
matchingMethod: AnyAlert
groupByEntities: []
createIncident: true
name: Pathlock TDnR - SAP Web Dispatcher HTTP Events
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
description: Detects security-relevant events from SAP Web Dispatcher HTTP logs, forwarded by Pathlock Threat Detection and Response. Web Dispatcher anomalies may indicate web application attacks, request smuggling, unauthorized access to backend SAP systems, or exploitation of SAP Fiori and S/4HANA web frontends.
id: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77
triggerThreshold: 0
queryPeriod: 1h
query: |
Pathlock_TDnR_CL
| where DataSource == "WD_HTTP_LOG"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs
version: 1.0.0
status: Available
eventGroupingSettings:
aggregationKind: SingleAlert
severity: Medium
requiredDataConnectors:
- connectorId: Pathlock_TDnR
dataTypes:
- Pathlock_TDnR_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_WD_HTTP_LOG.yaml
relevantTechniques:
- T1190
- T1071
tactics:
- InitialAccess
- CommandAndControl
entityMappings:
- fieldMappings:
- identifier: Name
columnName: Bname
entityType: Account
- fieldMappings:
- identifier: HostName
columnName: Hostname
entityType: Host
- fieldMappings:
- identifier: Address
columnName: SrcIp
entityType: IP
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77')]",
"properties": {
"alertRuleTemplateName": "2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77",
"customDetails": null,
"description": "Detects security-relevant events from SAP Web Dispatcher HTTP logs, forwarded by Pathlock Threat Detection and Response. Web Dispatcher anomalies may indicate web application attacks, request smuggling, unauthorized access to backend SAP systems, or exploitation of SAP Fiori and S/4HANA web frontends.",
"displayName": "Pathlock TDnR - SAP Web Dispatcher HTTP Events",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "Bname",
"identifier": "Name"
}
]
},
{
"entityType": "Host",
"fieldMappings": [
{
"columnName": "Hostname",
"identifier": "HostName"
}
]
},
{
"entityType": "IP",
"fieldMappings": [
{
"columnName": "SrcIp",
"identifier": "Address"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"incidentConfiguration": {
"createIncident": true,
"groupingConfiguration": {
"enabled": true,
"groupByAlertDetails": [],
"groupByCustomDetails": [],
"groupByEntities": [],
"lookbackDuration": "PT5H",
"matchingMethod": "AnyAlert",
"reopenClosedIncident": false
}
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Pathlock_TDnR/Analytic%20Rules/Pathlock_TDnR_WD_HTTP_LOG.yaml",
"query": "Pathlock_TDnR_CL\n| where DataSource == \"WD_HTTP_LOG\"\n| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,\n Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,\n MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT5H",
"suppressionEnabled": false,
"tactics": [
"CommandAndControl",
"InitialAccess"
],
"techniques": [
"T1071",
"T1190"
],
"templateVersion": "1.0.0",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}