Microsoft Sentinel medium experimental kql

Pathlock TDnR - GRC Access Control Change Documents

Detects changes to SAP GRC (Governance, Risk, and Compliance) access control configuration, forwarded by Pathlock Threat Detection and Response. Modifications to GRC settings may indicate attempts to bypass segregation of duties controls or disable risk monitoring.

View Source

Detection Logic

Pathlock_TDnR_CL
| where DataSource == "CHANGEDOC_GRAC"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs

Field Validations

Loading…

Comments (0)

Loading comments...