Microsoft Sentinel medium experimental kql

Pathlock TDnR - SAP Cloud Account Administration Events

Detects account administration events in SAP Cloud environments, forwarded by Pathlock Threat Detection and Response. Suspicious cloud account activities may indicate unauthorized provisioning, privilege escalation, or account takeover in SAP cloud tenants.

View Source

Detection Logic

Pathlock_TDnR_CL
| where DataSource == "CLOUD_ACCOUNT_LOGS"
| project TimeGenerated, Sysid, DataSource, Eventid, Instance, Hostname, Bname,
          Tcode, Report, Area, Subid, SrcIp, DestIp, AffectedUser, LogLine,
          MsgType, MsgId, MsgNo, MessageV1, MessageV2, MessageV3, MessageV4, CentralTs

Field Validations

Loading…

Comments (0)

Loading comments...