Microsoft Sentinel medium experimental kql

Pathlock TDnR - SAP BTP Cloud Foundry Events

Detects security events from SAP BTP Cloud Foundry environments, forwarded by Pathlock Threat Detection and Response. Anomalous BTP Cloud Foundry activity may indicate unauthorized application deployments, service account abuse, or data exfiltration from cloud-native SAP workloads.

View Source

Detection Logic

Pathlock_TDnR_CL
| where DataSource == "CLOUD_FOUNDRY_LOGS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs

Field Validations

Loading…

Comments (0)

Loading comments...