Microsoft Sentinel high experimental kql

Pathlock TDnR - Dynamic Access Control Events

Detects events from Pathlock Dynamic Access Control (DAC) for SAP, forwarded to Microsoft Sentinel. DAC events capture real-time access policy decisions and violations, including blocked transactions, emergency access grants, and policy bypass attempts that require immediate investigation.

View Source

Detection Logic

Pathlock_TDnR_CL
| where DataSource == "PATHLOCK_DAC"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs

Field Validations

Loading…

Comments (0)

Loading comments...