Back
Id8a4c9e2f-6b1d-4e7a-9c3f-2d5b8f1a6e4c
RulenameSAP BTP - Critical vulnerability finding in custom app
DescriptionIdentifies SAP BTP Application Vulnerability Report Service findings where the CVSS

score exceeds a configurable threshold (default 9.0, i.e. Critical severity). Such

findings indicate custom applications deployed on SAP BTP that carry vulnerable

open-source packages or components with a known, high-impact CVE. These risky

applications should be prioritized for remediation and reviewed for signs of

exploitation.
SeverityHigh
TacticsInitialAccess
TechniquesT1190
Required data connectorsSAPBTPAVL
KindScheduled
Query frequency1d
Query period1d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SAP%20BTP/Analytic%20Rules/BTP%20-%20Critical%20vulnerability%20finding%20in%20custom%20app.yaml
Version1.0.0
Arm template8a4c9e2f-6b1d-4e7a-9c3f-2d5b8f1a6e4c.json
Deploy To Azure
// Configurable CVSS threshold - lower this value to widen detection scope (default: 9.0 = Critical)
let cvssThreshold = 9.0;
SAPBTPAVL_CL
// Keep only the latest known state per finding, then apply the threshold so
// findings rescored below it are not alerted on from an older record
| summarize arg_max(TimeGenerated, *) by FindingId
| where MaxCvss >= cvssThreshold
| project
    TimeGenerated,
    FindingId,
    AppId,
    AppName,
    Description,
    MaxCvss,
    Severity,
    CvssVector,
    ActiveCves,
    PackageNames,
    Recommendation,
    VulnerabilityUrl,
    SubaccountId,
    SubaccountName,
    GlobalAccountId,
    GlobalAccountName,
    CfOrganizationName,
    SpaceName,
    Landscape,
    CloudApp = "SAP BTP"
relevantTechniques:
- T1190
tactics:
- InitialAccess
entityMappings:
- fieldMappings:
  - columnName: AppId
    identifier: AppId
  - columnName: AppName
    identifier: Name
  entityType: CloudApplication
- fieldMappings:
  - columnName: VulnerabilityUrl
    identifier: Url
  entityType: URL
triggerOperator: gt
description: |
  Identifies SAP BTP Application Vulnerability Report Service findings where the CVSS
  score exceeds a configurable threshold (default 9.0, i.e. Critical severity). Such
  findings indicate custom applications deployed on SAP BTP that carry vulnerable
  open-source packages or components with a known, high-impact CVE. These risky
  applications should be prioritized for remediation and reviewed for signs of
  exploitation.
triggerThreshold: 0
name: SAP BTP - Critical vulnerability finding in custom app
customDetails:
  SubaccountName: SubaccountName
  Landscape: Landscape
  GlobalAccountName: GlobalAccountName
  ActiveCves: ActiveCves
  FindingId: FindingId
  VulnerabilityUrl: VulnerabilityUrl
  CvssVector: CvssVector
  AppName: AppName
  MaxCvss: MaxCvss
  PackageNames: PackageNames
  Recommendation: Recommendation
queryFrequency: 1d
id: 8a4c9e2f-6b1d-4e7a-9c3f-2d5b8f1a6e4c
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SAP%20BTP/Analytic%20Rules/BTP%20-%20Critical%20vulnerability%20finding%20in%20custom%20app.yaml
version: 1.0.0
requiredDataConnectors:
- connectorId: SAPBTPAVL
  dataTypes:
  - SAPBTPAVL_CL
incidentConfiguration:
  groupingConfiguration:
    matchingMethod: Selected
    groupByCustomDetails:
    - AppName
    - SubaccountName
    enabled: true
    reopenClosedIncident: false
    lookbackDuration: P1D
  createIncident: true
queryPeriod: 1d
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: High
query: |
  // Configurable CVSS threshold - lower this value to widen detection scope (default: 9.0 = Critical)
  let cvssThreshold = 9.0;
  SAPBTPAVL_CL
  // Keep only the latest known state per finding, then apply the threshold so
  // findings rescored below it are not alerted on from an older record
  | summarize arg_max(TimeGenerated, *) by FindingId
  | where MaxCvss >= cvssThreshold
  | project
      TimeGenerated,
      FindingId,
      AppId,
      AppName,
      Description,
      MaxCvss,
      Severity,
      CvssVector,
      ActiveCves,
      PackageNames,
      Recommendation,
      VulnerabilityUrl,
      SubaccountId,
      SubaccountName,
      GlobalAccountId,
      GlobalAccountName,
      CfOrganizationName,
      SpaceName,
      Landscape,
      CloudApp = "SAP BTP"
status: Available
alertDetailsOverride:
  alertDisplayNameFormat: "SAP BTP: Critical vulnerability (CVSS {{MaxCvss}}) in app '{{AppName}}'"
  alertDescriptionFormat: "{{Description}} (subaccount '{{SubaccountName}}'). Details: {{VulnerabilityUrl}}"
kind: Scheduled
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/8a4c9e2f-6b1d-4e7a-9c3f-2d5b8f1a6e4c')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/8a4c9e2f-6b1d-4e7a-9c3f-2d5b8f1a6e4c')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "{{Description}} (subaccount '{{SubaccountName}}'). Details: {{VulnerabilityUrl}}",
          "alertDisplayNameFormat": "SAP BTP: Critical vulnerability (CVSS {{MaxCvss}}) in app '{{AppName}}'"
        },
        "alertRuleTemplateName": "8a4c9e2f-6b1d-4e7a-9c3f-2d5b8f1a6e4c",
        "customDetails": {
          "ActiveCves": "ActiveCves",
          "AppName": "AppName",
          "CvssVector": "CvssVector",
          "FindingId": "FindingId",
          "GlobalAccountName": "GlobalAccountName",
          "Landscape": "Landscape",
          "MaxCvss": "MaxCvss",
          "PackageNames": "PackageNames",
          "Recommendation": "Recommendation",
          "SubaccountName": "SubaccountName",
          "VulnerabilityUrl": "VulnerabilityUrl"
        },
        "description": "Identifies SAP BTP Application Vulnerability Report Service findings where the CVSS\nscore exceeds a configurable threshold (default 9.0, i.e. Critical severity). Such\nfindings indicate custom applications deployed on SAP BTP that carry vulnerable\nopen-source packages or components with a known, high-impact CVE. These risky\napplications should be prioritized for remediation and reviewed for signs of\nexploitation.\n",
        "displayName": "SAP BTP - Critical vulnerability finding in custom app",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "CloudApplication",
            "fieldMappings": [
              {
                "columnName": "AppId",
                "identifier": "AppId"
              },
              {
                "columnName": "AppName",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "URL",
            "fieldMappings": [
              {
                "columnName": "VulnerabilityUrl",
                "identifier": "Url"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "groupByCustomDetails": [
              "AppName",
              "SubaccountName"
            ],
            "lookbackDuration": "P1D",
            "matchingMethod": "Selected",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SAP%20BTP/Analytic%20Rules/BTP%20-%20Critical%20vulnerability%20finding%20in%20custom%20app.yaml",
        "query": "// Configurable CVSS threshold - lower this value to widen detection scope (default: 9.0 = Critical)\nlet cvssThreshold = 9.0;\nSAPBTPAVL_CL\n// Keep only the latest known state per finding, then apply the threshold so\n// findings rescored below it are not alerted on from an older record\n| summarize arg_max(TimeGenerated, *) by FindingId\n| where MaxCvss >= cvssThreshold\n| project\n    TimeGenerated,\n    FindingId,\n    AppId,\n    AppName,\n    Description,\n    MaxCvss,\n    Severity,\n    CvssVector,\n    ActiveCves,\n    PackageNames,\n    Recommendation,\n    VulnerabilityUrl,\n    SubaccountId,\n    SubaccountName,\n    GlobalAccountId,\n    GlobalAccountName,\n    CfOrganizationName,\n    SpaceName,\n    Landscape,\n    CloudApp = \"SAP BTP\"\n",
        "queryFrequency": "P1D",
        "queryPeriod": "P1D",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "InitialAccess"
        ],
        "techniques": [
          "T1190"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}