SAP

Telemetry Evidence

These values show how indexed rules identify SAP telemetry.

Kusto

  • Queried source table SAPBTPAuditLog_CL (16 rules)
  • Queried source table SAPETDAlerts_CL (5 rules)
  • Queried source table SAPETDInvestigations_CL (1 rule)
  • Queried source table Syslog (4 rules)
  • Query discriminator CollectorHostName = SAPLogServ (4 rules)
  • Source collection SAP LogServ (4 rules)

YARA-L

  • Product name SAP security audit (2 rules)
  • Product name SAP_GATEWAY (2 rules)
  • Product name SAP_HANA_AUDIT (2 rules)

Detection Rules

Kusto #

  • SAP BTP - Audit log service unavailable source high: Identifies SAP BTP subaccounts that have not reported audit logs for an unusual period. This could indicate that the audit log service has been disabled or tampered with, potentially by an attacker attempting to hide malicious activity. It may also indicate service key expiry or SAP BTP service availability problems.T1685, T1685.002
  • SAP BTP - Build Work Zone unauthorized access and role tampering source high: Identifies unauthorized OData access attempts and mass role/user deletions in SAP Build Work Zone Standard Edition. These events may indicate an attacker accessing restricted resources or removing access controls to cover their tracks.T1070, T1078, T1531
  • SAP BTP - Cloud Identity Service application configuration monitor source medium: Identifies CRUD operations on Application (SSO Domain/Service Provider) configurations within SAP Cloud Identity Service. This includes both SAML 2.0 and OpenID Connect applications. Unauthorized application creation could indicate an attacker establishing persistent access through a rogue federated application.T1134, T1556, T1606
  • SAP BTP - Cloud Integration access policy tampering source high: Identifies changes to access policies in SAP Cloud Integration. Access policies control authorization for integration artifacts, defining which users and roles can access specific integration flows and related content. Unauthorized access policy manipulation could indicate: - Attacker granting themselves access to sensitive integration artifacts - Removal of security controls to enable further malicious activity - Defense evasion by modifying artifact references to hide unauthorized accessT1222, T1548
  • SAP BTP - Cloud Integration artifact deployment source high: Identifies deployment and undeployment of integration artifacts in SAP Cloud Integration. Integration flows are executable code that can process, transform, and route data between systems. Unauthorized artifact deployment could indicate: - Attacker deploying malicious integration flows for data exfiltration - Deployment of rogue code for persistent access - Undeployment of critical integrations causing denial of serviceT1059, T1546
  • SAP BTP - Cloud Integration JDBC data source changes source high: Identifies deployment and undeployment of JDBC data source configurations in SAP Cloud Integration. JDBC data sources contain database connection credentials and configuration that enable integration flows to access backend databases. Unauthorized JDBC data source manipulation could indicate: - Attacker adding rogue database connections for data exfiltration - Credential theft by accessing stored database passwords - Modification of connection strings to redirect traffic to attacker-controlled systemsT1021, T1552
  • SAP BTP - Cloud Integration package import or transport source medium: Identifies import and transport operations for integration packages and artifacts in SAP Cloud Integration. Packages contain integration flows, mappings, scripts, and other artifacts that can be imported from external sources or transported between tenants. Unauthorized package operations could indicate: - Supply chain attack through malicious package import - Lateral movement between environments via artifact transport - Introduction of backdoors or rogue integration logicT1195, T1546
  • SAP BTP - Cloud Integration tampering with security material source medium: Identifies operations on security material (credentials, certificates, and keys) within SAP Cloud Integration. This includes credentials (passwords/secrets), X.509 certificates and key pairs, and PGP keys. Unauthorized manipulation of security material could indicate an attacker attempting to: - Gain access to external systems using stored credentials - Intercept or tamper with encrypted communications - Establish persistence through certificate manipulation - Cover tracks by deleting security artifactsT1070, T1552
  • SAP BTP - Failed access attempts across multiple BAS subaccounts source medium: Identifies failed Business Application Studio access attempts over a predefined number of subaccounts.T1526, T1595
  • SAP BTP - Malware detected in BAS dev space source medium: Identifies instances of malware detected using SAP internal malware agent within Business Application Studio dev spaces.T0873, T1072, T1584
Show 6 more

YARA-L #

Product-Filtered Rules

These rules use generic transport telemetry with a product-specific filter for SAP.

Kusto #

Other Index Content

This content is indexed for research but excluded from the detection-rule headline.

Kusto #

  • SAP ETD - Execution of Sensitive Function Module source medium: Identifies execution of a sensitive ABAP Function Module using the watchlists provided by the Microsoft Sentinel Solution for SAP Source Action: Execute a sensitive function module directly using SE37. Data Sources: SAP Enterprise Thread Detection Solution - Alerts
  • SAP ETD - Login from unexpected network source medium: Identifies logons from an unexpected network. Source Action: Logon to the backend system from an IP address which is not assigned to one of the networks. networks can be maintained in the "SAP - Networks" watchlist of the Microsoft Sentinel Solution for SAP package. Data Sources: SAP Enterprise Thread Detection Solution - Alerts
  • SAP ETD - No new data received source high: Identifies a complete gap in the SAP Enterprise Threat Detection (ETD) feed when no records have been ingested into the SAPETDAlerts_CL table within the configured time window (default 1 hour). A full-feed blackout may indicate that an adversary is tampering with the security telemetry pipeline (for example by stopping the SAP ETD collector, disabling the data connector, or blocking network egress to Microsoft Sentinel) to hide follow-on activity in the SAP landscape. Benign causes such as a service outage, connector failure, or maintenance window are also possible and should be ruled out during triage. This rule is complementary to the per-SAP-system rule "SAP ETD - SAP system stopped reporting data", which can help distinguish a targeted silencing of a single system from a full-feed blackout. To change the freshness threshold, update the LookbackPeriod variable in the query and align queryFrequency / queryPeriod accordingly.T1685
  • SAP ETD - SAP system stopped reporting data source high: Identifies a per-system silence when an individual SAP system (identified by its SID) that has recently been reporting to SAP Enterprise Threat Detection (ETD) stops producing new records in the SAPETDAlerts_CL table within the configured per-system grace period (default 2 hours). A targeted silence of a single SID may indicate that an adversary with access to the SAP system, the SAP ETD collector for that SID, or the data connector is selectively blocking security telemetry to hide follow-on activity while leaving the rest of the SAP ETD feed intact; benign causes such as connectivity issues, collector misconfiguration, or planned maintenance for that SID are also possible and should be ruled out during triage. The set of "expected" SIDs is derived from any system that has reported within the BaselineLookback period (default 7 days); systems silent for longer are considered decommissioned and are not alerted on. Tunable parameters at the top of the query: LookbackPeriod (silence threshold per SID; align with queryFrequency) and BaselineLookback (how far back to look to discover known SIDs; align with queryPeriod). This rule is complementary to the overall-feed rule "SAP ETD - No new data received".T1685
  • SAP ETD - Synch alerts source medium: Synch alerts coming in from SAP Enterprise Threat Detection into Microsoft Sentinel (one way)
  • SAP ETD - Synch investigations source high: Synch investigations coming in from SAP Enterprise Threat Detection into Microsoft Sentinel (one way)

Package-Only Rules

These rules appear in a SAP source package, but their queries do not identify SAP telemetry. They do not count toward Rules.

YARA-L #