Pathlock
Telemetry Evidence
These values show how indexed rules identify Pathlock telemetry.Kusto
Pathlock_TDnR_CL
Detection Rules
Kusto #
- Pathlock TDnR - ABAP Runtime Dumps source medium: Detects ABAP runtime dumps (short dumps) in SAP, forwarded by Pathlock Threat Detection and Response. Abnormal dump activity may indicate exploitation attempts, injection of malformed inputs, or application-layer attacks targeting SAP business processes.
T1082 - Pathlock TDnR - ABAP Source Code Changes source high: Detects changes to ABAP source code in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized ABAP code modifications may indicate backdoor installation, persistent access mechanisms, or insider threats targeting the SAP application layer.
T1505,T1685 - Pathlock TDnR - Authorization Check Value Changes (SU24) source high: Detects changes to authorization check values in the SU24 table in SAP, forwarded by Pathlock Threat Detection and Response. SU24 defines which authorization objects are checked for each transaction; unauthorized changes can effectively disable authorization checks and allow privilege escalation without modifying roles or profiles.
T1548,T1685 - Pathlock TDnR - Authorization Profile Changes source high: Detects changes to SAP authorization profiles, forwarded by Pathlock Threat Detection and Response. Unauthorized profile modifications may grant excessive privileges, create privilege escalation paths, or be used to establish persistent privileged access in SAP systems.
T1098,T1548 - Pathlock TDnR - Authorization Role Changes source high: Detects changes to SAP authorization roles (PFCG), forwarded by Pathlock Threat Detection and Response. Unauthorized role modifications are one of the most common SAP privilege escalation vectors and may be used to grant unauthorized access to sensitive transactions or data.
T1098,T1548 - Pathlock TDnR - Bank Master Data Changes source high: Detects changes to bank master data in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized modifications to bank data may indicate financial fraud, payment redirection, or business email compromise attacks targeting payment processes.
T1565 - Pathlock TDnR - Business Partner Bank Data Changes source high: Detects changes to bank master data for business partners in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to business partner bank accounts may indicate fraud targeting vendor or customer payments.
T1565 - Pathlock TDnR - Credit Card Data Changes source high: Detects changes to credit card records in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized modifications to credit card data may indicate financial fraud, PCI-DSS violations, or targeted attacks against payment data stored within SAP.
T1530,T1565 - Pathlock TDnR - Critical File Integrity Changes source high: Detects changes to checksums of critical SAP files, forwarded by Pathlock Threat Detection and Response. File integrity violations may indicate malware installation, unauthorized patching, or tampering with SAP executables and configuration files.
T1036,T1685 - Pathlock TDnR - CUA Settings Changes source medium: Detects changes to SAP Central User Administration (CUA) settings, forwarded by Pathlock Threat Detection and Response. Unauthorized CUA modifications may affect centralized user management across connected SAP systems and could be used to establish persistent access.
T1098
Show 67 more
- Pathlock TDnR - Database Cockpit Audit Events source medium: Detects security-relevant events from the SAP Database Administration Cockpit (DBACOCKPIT), forwarded by Pathlock Threat Detection and Response. Suspicious DBACOCKPIT activity may indicate unauthorized direct database access, privilege escalation, or attempts to bypass SAP application controls.
T1082,T1548 - Pathlock TDnR - DDIC Table Utility Changes (SE14) source high: Detects changes made using the DDIC table utility tool SE14 in SAP, forwarded by Pathlock Threat Detection and Response. SE14 operations can delete or restructure database tables, making this one of the highest-risk actions an SAP user can perform - often used to destroy audit trails or manipulate historical data.
T1685 - Pathlock TDnR - Debitor Change Documents source medium: Detects changes to debitor (customer) master records in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized modifications may indicate fraudulent manipulation of customer accounts or receivables data.
T1565 - Pathlock TDnR - Dynamic Access Control Events source high: Detects events from Pathlock Dynamic Access Control (DAC) for SAP, forwarded to Microsoft Sentinel. DAC events capture real-time access policy decisions and violations, including blocked transactions, emergency access grants, and policy bypass attempts that require immediate investigation.
T1134,T1548 - Pathlock TDnR - Emergency User (AdminTrack) Activity source high: Detects activity from emergency user accounts tracked by Pathlock AdminTrack in SAP, forwarded by Pathlock Threat Detection and Response. Emergency user (firefighter) account usage should always be reviewed as these accounts carry broad privileges and any unauthorized or unreviewed use may indicate insider threat or account takeover.
T1078,T1548 - Pathlock TDnR - Function Module Tested in Production source high: Detects execution of SAP function modules in a test environment context within production systems, forwarded by Pathlock Threat Detection and Response. This activity may indicate unauthorized code execution, exploitation of function module interfaces, or abuse of debugging capabilities.
T1059 - Pathlock TDnR - G/L Account Changes source medium: Detects changes to General Ledger (G/L) accounts in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized modifications to G/L accounts may indicate financial data manipulation, accounting fraud, or attempts to conceal unauthorised transactions.
T1565 - Pathlock TDnR - Generic SAP Change Documents source medium: Detects generic SAP change document events across all object classes, forwarded by Pathlock Threat Detection and Response. This broad datasource captures cross-functional object modifications that may indicate unauthorized data tampering or configuration changes.
T1565,T1685 - Pathlock TDnR - Generic Table Content Changes source high: Detects generic change documents for SAP table content, forwarded by Pathlock Threat Detection and Response. Direct table data modifications may bypass normal application validation and audit trails, and could indicate data manipulation, configuration tampering, or fraud concealment.
T1565,T1685 - Pathlock TDnR - Global System Change Setting Events source high: Detects changes to global SAP system change settings, forwarded by Pathlock Threat Detection and Response. System change option modifications (e.g. enabling software changes in production) bypass change management processes and may allow unauthorized code or configuration changes to be applied directly to production systems.
T1098,T1685 - Pathlock TDnR - GRC Access Control Change Documents source medium: Detects changes to SAP GRC (Governance, Risk, and Compliance) access control configuration, forwarded by Pathlock Threat Detection and Response. Modifications to GRC settings may indicate attempts to bypass segregation of duties controls or disable risk monitoring.
T1548 - Pathlock TDnR - HANA Standalone DB Connection Events source medium: Detects security events from HANA standalone database connections via DBCON in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized DBCON connections allow direct database access and may be used for lateral movement or to bypass SAP application-layer controls.
T1021 - Pathlock TDnR - HR User Master Change Requests source medium: Detects change requests to the HR user master data in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized HR data changes may indicate targeted manipulation of employee records, payroll fraud, or exfiltration of sensitive personnel information.
T1213,T1565 - Pathlock TDnR - IBAN Change Documents source high: Detects changes to IBAN (International Bank Account Number) records in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized IBAN modifications are a strong indicator of payment fraud or account takeover targeting financial transactions.
T1565 - Pathlock TDnR - ICF Web Service Changes source high: Detects changes to SAP Internet Communication Framework (ICF) web service configuration, forwarded by Pathlock Threat Detection and Response. Unauthorized ICF changes may expose new attack surfaces, enable access to sensitive OData or SOAP services, or re-enable previously disabled dangerous services.
T1505 - Pathlock TDnR - ICM Security Events source medium: Detects security events from the SAP Internet Communication Manager (ICM) security log, forwarded by Pathlock Threat Detection and Response. ICM anomalies may indicate SSL/TLS configuration attacks, HTTP request smuggling, or attempts to exploit the ICM layer of SAP web-facing components.
T1685 - Pathlock TDnR - J2EE Security Audit Events source medium: Detects events from the SAP J2EE (Java) security audit log, forwarded by Pathlock Threat Detection and Response. Security audit events from the Java stack may reveal authentication failures, authorization violations, or exploitation attempts targeting SAP NetWeaver Application Server Java.
T1082 - Pathlock TDnR - J2EE Security Events source medium: Detects security events from SAP J2EE (Java) engine security logs, forwarded by Pathlock Threat Detection and Response. J2EE security anomalies may indicate web application attacks, unauthorized access to SAP NetWeaver Java services, or exploitation of Java-based SAP components.
T1082,T1190 - Pathlock TDnR - Kerberos Keytab Changes source high: Detects changes to Kerberos keytab configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to Kerberos settings may indicate credential theft, SSO bypass attempts, or persistent access mechanisms leveraging Kerberos delegation.
T1098,T1558 - Pathlock TDnR - LDAP Synchronization Application Log Events source medium: Detects security events from the SAP LDAP synchronization application log (SLG1), forwarded by Pathlock Threat Detection and Response. LDAP sync anomalies may indicate unauthorized identity directory manipulation, credential harvesting via LDAP queries, or synchronization abuse to propagate unauthorized access.
T1552 - Pathlock TDnR - Logical OS Command Changes source high: Detects changes to logical OS command definitions in SAP (transaction SM49), forwarded by Pathlock Threat Detection and Response. Modifications to OS commands may enable arbitrary OS-level code execution within the SAP system context, representing a critical escalation vector.
T1059,T1543 - Pathlock TDnR - Missing SAP Security Notes source medium: Detects alerts for missing SAP security notes (OSS Notes) in the environment, forwarded by Pathlock Threat Detection and Response. Unpatched SAP systems with known CVEs represent a significant attack surface and may be actively exploited by threat actors targeting SAP vulnerabilities.
T1082 - Pathlock TDnR - Multiple Login Sessions Detected source medium: Detects events from SAP multiple login monitoring (Table USR41), forwarded by Pathlock Threat Detection and Response. Multiple concurrent sessions from different sources may indicate credential sharing, session hijacking, or compromised accounts being used simultaneously by an attacker and the legitimate user.
T1078,T1110 - Pathlock TDnR - OData Application Log Events source medium: Detects security events from SAP OData service application logs (SLG1), forwarded by Pathlock Threat Detection and Response. OData anomalies may indicate API abuse, unauthorized mass data extraction via OData endpoints, or exploitation of SAP Fiori and S/4HANA OData services.
T1048,T1213 - Pathlock TDnR - Outbound SAP SMTP Email source medium: Detects outbound SMTP email activity from SAP systems, forwarded by Pathlock Threat Detection and Response. Anomalous outbound email patterns may indicate data exfiltration, unauthorized use of SAP email functions to send sensitive business data outside the organization.
T1048 - Pathlock TDnR - Outgoing Spool Print Job Events source medium: Detects recording of outgoing spool print jobs in SAP, forwarded by Pathlock Threat Detection and Response. Anomalous print job activity may indicate unauthorized printing of sensitive documents, data exfiltration via print-to-file operations, or misuse of SAP output management.
T1048 - Pathlock TDnR - Pathlock Security Radar Internal Events source medium: Detects internal events generated by the Pathlock Security Radar platform, forwarded to Microsoft Sentinel. These events include platform health indicators, configuration changes, and self-monitoring alerts that may require SOC attention.
T1082 - Pathlock TDnR - Payment Request Changes source medium: Detects changes to payment requests in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized modifications to payment requests may indicate financial fraud, duplicate payment schemes, or manipulation of treasury processes.
T1565 - Pathlock TDnR - RFC Connection Changes source high: Detects changes to RFC (Remote Function Call) connection definitions in SAP (transaction SM59), forwarded by Pathlock Threat Detection and Response. Unauthorized RFC changes may introduce backdoor connections, redirect communications to malicious systems, or enable lateral movement across SAP landscapes.
T1021,T1098 - Pathlock TDnR - RiskTrack Audit Results source high: Detects Pathlock RiskTrack audit results forwarded to Microsoft Sentinel. RiskTrack findings represent completed risk assessments identifying segregation of duties conflicts, critical access violations, and compliance gaps that require remediation or SOC awareness.
T1082 - Pathlock TDnR - SAP Authorization Changes source high: Detects changes to SAP authorization objects, forwarded by Pathlock Threat Detection and Response. Unauthorized authorization changes may be used to escalate privileges, bypass access controls, or create persistent privileged access in SAP systems.
T1098,T1548 - Pathlock TDnR - SAP Batch Job Events source medium: Detects security-relevant SAP batch processing events, forwarded by Pathlock Threat Detection and Response. Malicious or unauthorized batch jobs may be used to execute code, exfiltrate data, or establish persistent tasks within the SAP environment.
T1053,T1059 - Pathlock TDnR - SAP BTP Cloud Foundry Events source medium: Detects security events from SAP BTP Cloud Foundry environments, forwarded by Pathlock Threat Detection and Response. Anomalous BTP Cloud Foundry activity may indicate unauthorized application deployments, service account abuse, or data exfiltration from cloud-native SAP workloads.
T1082 - Pathlock TDnR - SAP Client Configuration Changes source high: Detects changes to SAP client configuration settings, forwarded by Pathlock Threat Detection and Response. Changes to client settings such as enabling client-independent changes or transport settings may indicate attempts to bypass change management controls.
T1098,T1685 - Pathlock TDnR - SAP Cloud Account Administration Events source medium: Detects account administration events in SAP Cloud environments, forwarded by Pathlock Threat Detection and Response. Suspicious cloud account activities may indicate unauthorized provisioning, privilege escalation, or account takeover in SAP cloud tenants.
T1078,T1136 - Pathlock TDnR - SAP Cloud Connector Events source medium: Detects security events from the SAP Cloud Connector (on-premise agent), forwarded by Pathlock Threat Detection and Response. Cloud Connector anomalies may indicate unauthorized configuration changes, tunnel abuse, or attempts to exploit the SAP Cloud Connector as a pivot point between on-premise and cloud environments.
T1021 - Pathlock TDnR - SAP Download Observer Events source medium: Detects download events captured by the Pathlock DownLoad Observer in SAP, forwarded to Microsoft Sentinel. Unusual download patterns may indicate bulk data exfiltration, unauthorized extraction of sensitive SAP data, or insider threat activity involving large-scale data downloads.
T1048 - Pathlock TDnR - SAP HANA Database Audit Trail source medium: Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database.
T1078,T1082 - Pathlock TDnR - SAP HANA Parameter Changes source medium: Detects changes to SAP HANA database configuration parameters, forwarded by Pathlock Threat Detection and Response. Unauthorized HANA parameter modifications may be used to disable security controls, weaken audit logging, or alter database behavior to facilitate attacks.
T1685 - Pathlock TDnR - SAP HTTP Webserver Events source medium: Detects security-relevant events from the SAP HTTP webserver logfile, forwarded by Pathlock Threat Detection and Response. Anomalous HTTP activity may indicate web-based attacks, unauthorized access to SAP web services, or command-and-control communication.
T1071,T1190 - Pathlock TDnR - SAP Instance Profile Changes source high: Detects changes to SAP instance profile parameters (RZ10), forwarded by Pathlock Threat Detection and Response. Instance profile modifications can alter security-critical parameters such as login/password_max_new_valid, auth/rfc_authority_check, or rec/client, potentially weakening system security posture.
T1098,T1685 - Pathlock TDnR - SAP Public Cloud Security Audit Events source medium: Detects security audit log events from SAP Public Cloud systems, forwarded by Pathlock Threat Detection and Response. Public cloud security audit events capture authentication, authorization, and configuration activity in SAP S/4HANA Cloud and other SAP Public Cloud environments.
T1082 - Pathlock TDnR - SAP Read Access Logging Audit source medium: Detects SAP Read Access Logging (RAL) audit changelog events, forwarded by Pathlock Threat Detection and Response. RAL audit events capture changes to which sensitive data fields are being logged, and modifications may indicate attempts to disable read access monitoring for sensitive data.
T1213 - Pathlock TDnR - SAP Read Access Logging Data source medium: Detects SAP Read Access Logging (RAL) data events capturing actual sensitive data access, forwarded by Pathlock Threat Detection and Response. RAL data events record when users access sensitive fields (e.g. salary data, personal information) and may indicate data harvesting or insider threat activity.
T1048,T1213 - Pathlock TDnR - SAP RFC Gateway Events source medium: Detects security-relevant events from the SAP RFC gateway logfile, forwarded by Pathlock Threat Detection and Response. Suspicious gateway activity may indicate unauthorized RFC connections, lateral movement across SAP systems, or command-and-control communication through the gateway.
T1021,T1071 - Pathlock TDnR - SAP Router Log Events source medium: Detects security-relevant events from the SAP Router log, forwarded by Pathlock Threat Detection and Response. SAP Router events may reveal unauthorized external connections, suspicious routing patterns, or attempts to use the SAP Router as a pivot point for lateral movement.
T1021,T1572 - Pathlock TDnR - SAP Security Audit Log Events source high: Detects security-relevant events from the SAP Security Audit Log (SM20), forwarded by Pathlock Threat Detection and Response. The Security Audit Log captures critical security events including failed logons, authorization failures, and restricted transactions - anomalies here are strong indicators of attack activity or insider threats.
T1082,T1685 - Pathlock TDnR - SAP System Job Monitoring Events source medium: Detects monitoring events from SAP system jobs (SJOBREPO), forwarded by Pathlock Threat Detection and Response. Anomalies in system job execution may indicate unauthorized task scheduling, manipulation of critical background processes, or use of system jobs as a persistence mechanism.
T1053 - Pathlock TDnR - SAP System Log Events source medium: Detects security-relevant events from the SAP System Log (SM21), forwarded by Pathlock Threat Detection and Response. System log events capture low-level system activity including kernel errors, authorization violations, and system configuration events that may indicate attacks or misuse.
T1082 - Pathlock TDnR - SAP Web Dispatcher HTTP Events source medium: Detects security-relevant events from SAP Web Dispatcher HTTP logs, forwarded by Pathlock Threat Detection and Response. Web Dispatcher anomalies may indicate web application attacks, request smuggling, unauthorized access to backend SAP systems, or exploitation of SAP Fiori and S/4HANA web frontends.
T1071,T1190 - Pathlock TDnR - SE16N Direct Table Change Documents source high: Detects direct table data changes made via SE16N (Table Browser) in SAP, forwarded by Pathlock Threat Detection and Response. SE16N changes bypass normal application workflows and audit trails, making them a high-risk activity that could indicate data manipulation, log tampering, or unauthorized direct database modifications.
T1048,T1685 - Pathlock TDnR - Spool Job Changes source medium: Detects changes to SAP spool jobs, forwarded by Pathlock Threat Detection and Response. Unauthorized spool job manipulations may indicate tampering with scheduled output, redirection of sensitive reports, or data collection activity involving SAP output management.
T1213 - Pathlock TDnR - STRUST PSE Certificate Changes source high: Detects changes to STRUST PSE (Personal Security Environment) certificate files in SAP, forwarded by Pathlock Threat Detection and Response. PSE modifications may indicate certificate tampering, introduction of rogue trusted certificates, or preparation for man-in-the-middle attacks against SAP communication channels.
T1552,T1553 - Pathlock TDnR - SU24 Table USOBT_C Changes source medium: Detects changes to the SU24 authorization check table USOBT_C in SAP, forwarded by Pathlock Threat Detection and Response. USOBT_C defines default authorization field values for transactions; unauthorized changes may allow privilege escalation by modifying authorization check behavior.
T1548,T1685 - Pathlock TDnR - SU24 Table USOBX_C Changes source medium: Detects changes to the SU24 authorization check table USOBX_C in SAP, forwarded by Pathlock Threat Detection and Response. USOBX_C controls whether authorization checks are active for transactions; unauthorized changes may disable security checks, enabling unauthorized access.
T1548,T1685 - Pathlock TDnR - Switchable Authorization Design Changes source high: Detects changes to Switchable Authorizations (SACF) design-time configuration in SAP, forwarded by Pathlock Threat Detection and Response. Modifications to switchable authorization design may disable security-relevant authorization checks, allowing bypasses of access controls without removing actual authorizations.
T1548,T1685 - Pathlock TDnR - Switchable Authorization Runtime Changes source high: Detects runtime changes to Switchable Authorizations (SACF) in SAP, forwarded by Pathlock Threat Detection and Response. Runtime SACF modifications take immediate effect and can instantly disable authorization checks in production, representing a critical real-time security control bypass.
T1548,T1685 - Pathlock TDnR - System Security Policy Changes source high: Detects changes to the SAP system security policy, forwarded by Pathlock Threat Detection and Response. Modifications to security policies may indicate attempts to weaken SAP's built-in security controls, lower password complexity, or disable audit logging.
T1098,T1685 - Pathlock TDnR - Table Parameter Setting Changes source high: Detects changes to SAP table parameter settings, forwarded by Pathlock Threat Detection and Response. Table parameter modifications may affect security-relevant settings, buffering behavior, or data access controls that could be exploited to weaken the overall security posture.
T1685 - Pathlock TDnR - TMS Transport and Import Events source high: Detects SAP Transport Management System (TMS) transport and import events, forwarded by Pathlock Threat Detection and Response. Unauthorized transports may introduce malicious code changes, configuration weaknesses, or backdoors into production SAP systems, bypassing normal change management and approval processes.
T1059,T1543 - Pathlock TDnR - Transaction and Report Statistics source medium: Detects security-relevant transaction and report usage statistics from SAP STAD, forwarded by Pathlock Threat Detection and Response. Unusual usage patterns such as mass execution of sensitive transactions, high-frequency report runs, or access by unexpected users may indicate reconnaissance or data harvesting.
T1082 - Pathlock TDnR - User Access Management Password Resets source medium: Detects password reset events from the Pathlock User Access Management module in SAP, forwarded to Microsoft Sentinel. Unexpected or bulk password resets may indicate account takeover preparation, credential stuffing followup, or unauthorized use of administrative password reset capabilities.
T1078,T1098 - Pathlock TDnR - User Authorization Buffer Manipulation source high: Detects unauthorized manipulations of the SAP user authorization buffer (USRBF2), forwarded by Pathlock Threat Detection and Response. Direct manipulation of the authorization buffer bypasses the normal role/profile assignment process and can grant arbitrary privileges to any user without leaving a trace in standard authorization management logs.
T1548,T1685 - Pathlock TDnR - User Master Data Changes source high: Detects changes to SAP user master data (SU01), forwarded by Pathlock Threat Detection and Response. User master data modifications include password changes, account locking/unlocking, validity date changes, and group assignments - any of which can be used to create persistent unauthorized access or facilitate account takeover.
T1098,T1548 - Pathlock TDnR - User-Profile Assignment Changes source high: Detects changes to user-to-profile assignments in SAP (SU01 profile tab), forwarded by Pathlock Threat Detection and Response. Unauthorized profile assignments can grant users broad authorizations outside of the role-based access control framework, bypassing segregation-of-duties controls.
T1098,T1548 - Pathlock TDnR - User-Role Assignment Changes source high: Detects changes to user-to-role assignments in SAP (SU01 roles tab), forwarded by Pathlock Threat Detection and Response. Unauthorized role assignments are the primary mechanism for granting and revoking SAP access, and unexpected changes may indicate privilege escalation, account backdooring, or unauthorized access provisioning.
T1098,T1548 - Pathlock TDnR - Vendor Change Documents source medium: Detects changes to vendor (creditor) master records in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized vendor modifications may indicate fraud targeting accounts payable processes, including payment redirection to attacker-controlled accounts.
T1565