Microsoft Sentinel medium experimental kql
Pathlock TDnR - SAP BTP Cloud Foundry Events
Detects security events from SAP BTP Cloud Foundry environments, forwarded by Pathlock Threat Detection and Response. Anomalous BTP Cloud Foundry activity may indicate unauthorized application deployments, service account abuse, or data exfiltration from cloud-native SAP workloads.
Detection Logic
Pathlock_TDnR_CL
| where DataSource == "CLOUD_FOUNDRY_LOGS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs Field Validations
Loading…
Comments (0)
Loading comments...