SAP
Telemetry Evidence
These values show how indexed rules identify SAP telemetry.Kusto
SAPBTPAuditLog_CL SAPETDAlerts_CL SAPETDInvestigations_CL Syslog CollectorHostName = SAPLogServ SAP LogServ YARA-L
SAP security audit SAP_GATEWAY SAP_HANA_AUDIT
Detection Rules
Kusto #
- SAP BTP - Audit log service unavailable source high: Identifies SAP BTP subaccounts that have not reported audit logs for an unusual period. This could indicate that the audit log service has been disabled or tampered with, potentially by an attacker attempting to hide malicious activity. It may also indicate service key expiry or SAP BTP service availability problems.
T1685,T1685.002 - SAP BTP - Build Work Zone unauthorized access and role tampering source high: Identifies unauthorized OData access attempts and mass role/user deletions in SAP Build Work Zone Standard Edition. These events may indicate an attacker accessing restricted resources or removing access controls to cover their tracks.
T1070,T1078,T1531 - SAP BTP - Cloud Identity Service application configuration monitor source medium: Identifies CRUD operations on Application (SSO Domain/Service Provider) configurations within SAP Cloud Identity Service. This includes both SAML 2.0 and OpenID Connect applications. Unauthorized application creation could indicate an attacker establishing persistent access through a rogue federated application.
T1134,T1556,T1606 - SAP BTP - Cloud Integration access policy tampering source high: Identifies changes to access policies in SAP Cloud Integration. Access policies control authorization for integration artifacts, defining which users and roles can access specific integration flows and related content. Unauthorized access policy manipulation could indicate: - Attacker granting themselves access to sensitive integration artifacts - Removal of security controls to enable further malicious activity - Defense evasion by modifying artifact references to hide unauthorized access
T1222,T1548 - SAP BTP - Cloud Integration artifact deployment source high: Identifies deployment and undeployment of integration artifacts in SAP Cloud Integration. Integration flows are executable code that can process, transform, and route data between systems. Unauthorized artifact deployment could indicate: - Attacker deploying malicious integration flows for data exfiltration - Deployment of rogue code for persistent access - Undeployment of critical integrations causing denial of service
T1059,T1546 - SAP BTP - Cloud Integration JDBC data source changes source high: Identifies deployment and undeployment of JDBC data source configurations in SAP Cloud Integration. JDBC data sources contain database connection credentials and configuration that enable integration flows to access backend databases. Unauthorized JDBC data source manipulation could indicate: - Attacker adding rogue database connections for data exfiltration - Credential theft by accessing stored database passwords - Modification of connection strings to redirect traffic to attacker-controlled systems
T1021,T1552 - SAP BTP - Cloud Integration package import or transport source medium: Identifies import and transport operations for integration packages and artifacts in SAP Cloud Integration. Packages contain integration flows, mappings, scripts, and other artifacts that can be imported from external sources or transported between tenants. Unauthorized package operations could indicate: - Supply chain attack through malicious package import - Lateral movement between environments via artifact transport - Introduction of backdoors or rogue integration logic
T1195,T1546 - SAP BTP - Cloud Integration tampering with security material source medium: Identifies operations on security material (credentials, certificates, and keys) within SAP Cloud Integration. This includes credentials (passwords/secrets), X.509 certificates and key pairs, and PGP keys. Unauthorized manipulation of security material could indicate an attacker attempting to: - Gain access to external systems using stored credentials - Intercept or tamper with encrypted communications - Establish persistence through certificate manipulation - Cover tracks by deleting security artifacts
T1070,T1552 - SAP BTP - Failed access attempts across multiple BAS subaccounts source medium: Identifies failed Business Application Studio access attempts over a predefined number of subaccounts.
T1526,T1595 - SAP BTP - Malware detected in BAS dev space source medium: Identifies instances of malware detected using SAP internal malware agent within Business Application Studio dev spaces.
T0873,T1072,T1584
Show 6 more
- SAP BTP - Mass user deletion in a sub account source medium: Identifies user account deletion activity where the amount of deleted users exceeds a predefined threshold.
T0813,T0826,T0827,T1485,T1489,T1531 - SAP BTP - Mass user deletion in Cloud Identity Service source medium: Identifies mass user deletion activity in SAP Cloud Identity Service where the amount of deleted users exceeds a predefined threshold.
T0813,T0826,T0827,T1485,T1489,T1531 - SAP BTP - Trust and authorization Identity Provider monitor source medium: Identifies CRUD operations on Identity Provider settings within a sub account.
T1134,T1556,T1606 - SAP BTP - Unaudited custom app with login-only activity source medium: Identifies SAP BTP custom applications (CloudFoundry, SAP CAP, etc.) that only produce XSUAA authentication events (TokenIssuedEvent, ClientAuthenticationSuccess) but have not generated any business audit log activity in the past 7 days. This pattern indicates that the application has not implemented audit logging (e.g., missing @AuditLog annotations in CAP or missing audit log service bindings), creating a security blind spot where user actions within the application are invisible to monitoring. The 7-day lookback avoids false positives for properly instrumented apps whose users simply have not performed auditable actions in the current session. Attackers could exploit such unaudited applications to perform malicious operations without detection.
T1685,T1685.002 - SAP BTP - User added to Cloud Identity Service privileged Administrators list source high: Identifies when a user is granted privileged administrator permissions in SAP Cloud Identity Service. These permissions include managing Identity Providers, Service Providers, Users, Groups, and Access controls.
T0859,T1078 - SAP BTP - User added to sensitive privileged role collection source low: Identifies identity management actions whereby a user is added to a set of monitored privileged role collections.
T0859,T1078
YARA-L #
- sap gateway acl bypass attempt source low: Detects rejected connections by Gateway ACLs (secinfo/reginfo), indicating an attempt to bypass network-layer security.
T1190 - sap gateway ufo table access source high: Detects external RFC calls to generic table-read modules via the SAP Gateway.
T1082 - sap hanadb audit trail policy changes source high: Detects changes to SAP HANA audit policies (Create, Alter, Drop) which could indicate an attempt to evade logging.
T1685 - sap hanadb deactivation of audit trail source critical: Detects the deactivation of the global auditing state in SAP HANA, which stops all audit logging.
T1685 - sap multiple password changes source medium: Detects multiple password changes (BU2) by a single actor or targeting a single user across systems.
T1098 - sap suspected data exfiltration source medium: Detects high-volume data downloads (AUY) from SAP to a local frontend file, potentially indicating exfiltration.
T1041
Product-Filtered Rules
These rules use generic transport telemetry with a product-specific filter for SAP.Kusto #
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Kusto #
LookbackPeriod variable in the query and align queryFrequency / queryPeriod accordingly.T1685BaselineLookback period (default 7 days); systems silent for longer are considered decommissioned and are not alerted on. Tunable parameters at the top of the query: LookbackPeriod (silence threshold per SID; align with queryFrequency) and BaselineLookback (how far back to look to discover known SIDs; align with queryPeriod). This rule is complementary to the overall-feed rule "SAP ETD - No new data received".T1685
Package-Only Rules
These rules appear in a SAP source package, but their queries do not identify SAP telemetry. They do not count toward Rules.YARA-L #
T1078T1110T1098T1098T1098T1098T1098T1098T1564T1685T1059T1129T1098T1136T1078T1078T1685T1136T1129T1098T1098T1005T1005T1685T1136