Analytic rule catalog
SAP BTP - Mass user deletion in Cloud Identity Service
Back
| Id | a3b8e7c4-5f2d-4a1e-9c6b-8d7f3e2a1b0c |
| Rulename | SAP BTP - Mass user deletion in Cloud Identity Service |
| Description | Identifies mass user deletion activity in SAP Cloud Identity Service where the amount of deleted users exceeds a predefined threshold. |
| Severity | Medium |
| Tactics | Impact |
| Techniques | T1531 T1485 T1489 T0813 T0826 T0827 |
| Required data connectors | SAPBTPAuditEvents |
| Kind | Scheduled |
| Query frequency | 1h |
| Query period | 1h |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SAP%20BTP/Analytic%20Rules/BTP%20-%20Mass%20user%20deletion%20in%20Cloud%20Identity%20Service.yaml |
| Version | 3.0.1 |
| Arm template | a3b8e7c4-5f2d-4a1e-9c6b-8d7f3e2a1b0c.json |
let bulk_delete_threshold = 10;
SAPBTPAuditLog_CL
| extend data_s = tostring(Message.data)
| extend action = extract(@"action=""([^""]+)""", 1, data_s),
objectType = extract(@"objectType=""([^""]+)""", 1, data_s),
impactedUser = extract(@"serviceProviderName=""([^""]+)""", 1, data_s)
| where action == "delete"
| where objectType == "authorization"
| where isnotempty(impactedUser)
| summarize
Start = min(UpdatedOn),
End = max(UpdatedOn),
DeleteCount = count(),
DeletedUsers = make_set(impactedUser, 100)
by UserName, Tenant, SpaceId
| where array_length(DeletedUsers) > bulk_delete_threshold
| project Start, End, UserName, DeletedUsers, DeleteCount, Tenant, SpaceId, CloudApp = "SAP BTP"
| extend AccountName = split(UserName, "@")[0], UPNSuffix = split(UserName, "@")[1]
relevantTechniques:
- T1531
- T1485
- T1489
- T0813
- T0826
- T0827
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
severity: Medium
description: Identifies mass user deletion activity in SAP Cloud Identity Service where the amount of deleted users exceeds a predefined threshold.
status: Available
id: a3b8e7c4-5f2d-4a1e-9c6b-8d7f3e2a1b0c
query: |
let bulk_delete_threshold = 10;
SAPBTPAuditLog_CL
| extend data_s = tostring(Message.data)
| extend action = extract(@"action=""([^""]+)""", 1, data_s),
objectType = extract(@"objectType=""([^""]+)""", 1, data_s),
impactedUser = extract(@"serviceProviderName=""([^""]+)""", 1, data_s)
| where action == "delete"
| where objectType == "authorization"
| where isnotempty(impactedUser)
| summarize
Start = min(UpdatedOn),
End = max(UpdatedOn),
DeleteCount = count(),
DeletedUsers = make_set(impactedUser, 100)
by UserName, Tenant, SpaceId
| where array_length(DeletedUsers) > bulk_delete_threshold
| project Start, End, UserName, DeletedUsers, DeleteCount, Tenant, SpaceId, CloudApp = "SAP BTP"
| extend AccountName = split(UserName, "@")[0], UPNSuffix = split(UserName, "@")[1]
requiredDataConnectors:
- connectorId: SAPBTPAuditEvents
dataTypes:
- SAPBTPAuditLog_CL
version: 3.0.1
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SAP%20BTP/Analytic%20Rules/BTP%20-%20Mass%20user%20deletion%20in%20Cloud%20Identity%20Service.yaml
name: SAP BTP - Mass user deletion in Cloud Identity Service
tactics:
- Impact
entityMappings:
- entityType: Account
fieldMappings:
- columnName: AccountName
identifier: Name
- columnName: UPNSuffix
identifier: UPNSuffix
- entityType: CloudApplication
fieldMappings:
- columnName: CloudApp
identifier: Name
kind: Scheduled
triggerThreshold: 0
eventGroupingSettings:
aggregationKind: SingleAlert
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"apiVersion": "2024-01-01-preview",
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/a3b8e7c4-5f2d-4a1e-9c6b-8d7f3e2a1b0c')]",
"kind": "Scheduled",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/a3b8e7c4-5f2d-4a1e-9c6b-8d7f3e2a1b0c')]",
"properties": {
"alertRuleTemplateName": "a3b8e7c4-5f2d-4a1e-9c6b-8d7f3e2a1b0c",
"customDetails": null,
"description": "Identifies mass user deletion activity in SAP Cloud Identity Service where the amount of deleted users exceeds a predefined threshold.",
"displayName": "SAP BTP - Mass user deletion in Cloud Identity Service",
"enabled": true,
"entityMappings": [
{
"entityType": "Account",
"fieldMappings": [
{
"columnName": "AccountName",
"identifier": "Name"
},
{
"columnName": "UPNSuffix",
"identifier": "UPNSuffix"
}
]
},
{
"entityType": "CloudApplication",
"fieldMappings": [
{
"columnName": "CloudApp",
"identifier": "Name"
}
]
}
],
"eventGroupingSettings": {
"aggregationKind": "SingleAlert"
},
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/SAP%20BTP/Analytic%20Rules/BTP%20-%20Mass%20user%20deletion%20in%20Cloud%20Identity%20Service.yaml",
"query": "let bulk_delete_threshold = 10;\nSAPBTPAuditLog_CL\n| extend data_s = tostring(Message.data)\n| extend action = extract(@\"action=\"\"([^\"\"]+)\"\"\", 1, data_s),\n objectType = extract(@\"objectType=\"\"([^\"\"]+)\"\"\", 1, data_s),\n impactedUser = extract(@\"serviceProviderName=\"\"([^\"\"]+)\"\"\", 1, data_s)\n| where action == \"delete\"\n| where objectType == \"authorization\"\n| where isnotempty(impactedUser)\n| summarize\n Start = min(UpdatedOn),\n End = max(UpdatedOn),\n DeleteCount = count(),\n DeletedUsers = make_set(impactedUser, 100)\n by UserName, Tenant, SpaceId\n| where array_length(DeletedUsers) > bulk_delete_threshold\n| project Start, End, UserName, DeletedUsers, DeleteCount, Tenant, SpaceId, CloudApp = \"SAP BTP\"\n| extend AccountName = split(UserName, \"@\")[0], UPNSuffix = split(UserName, \"@\")[1]\n",
"queryFrequency": "PT1H",
"queryPeriod": "PT1H",
"severity": "Medium",
"status": "Available",
"subTechniques": [],
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"tactics": [
"Impact"
],
"techniques": [
"T1485",
"T1489",
"T1531"
],
"templateVersion": "3.0.1",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
},
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
}
]
}