Azure-Samples / Azure-Samples/Sentinel-For-SAP-Community
Track agent-only analytics rules as candidates for community extensions
- Vorherrschende Sprache
- Keine Sprachdaten
- Sterne
- 2
- Forks
- 5
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
The Microsoft Sentinel for SAP agent-based (containerized) data connector is being deprecated in favor of the [agentless SAP connector](https://learn.microsoft.com/azure/sentinel/sap/deployment-overview). As part of the docs cleanup ([MicrosoftDocs/defender-docs-pr#8934](https://github.com/MicrosoftDocs/defender-docs-pr/pull/8934)), several analytics rules that shipped with the agent-based solution are being removed from the official docs because they depend on data sources the agentless connector doesn't collect today.
To preserve the value of those detections for existing customers migrating to agentless, this issue tracks candidates for inclusion in the community extension packages (for example, the [baseline-extension-package](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts/solution-packages/baseline-extension-package), analogous to the existing `pahi-legacy-reader` extension for the `SAPSystemParameters` watchlist).
### Rule candidates by MITRE category
**Initial access**
- `SAP - Informational - Lifecycle - SAP Notes were implemented in system` (SAP Change Requests log)
- `SAP - (Preview) AS JAVA - Sensitive Privileged User Signed In` (SAPJAVAFilesLog)
- `SAP - (Preview) AS JAVA - Sign-In from Unexpected Network` (SAPJAVAFilesLog)
**Data exfiltration**
- `SAP - Multiple Spool Executions` (SAP Spool Log)
- `SAP - Multiple Spool Output Executions` (SAP Spool Output Log)
- `SAP - Spool Takeover` (SAP Spool Log + Spool Output Log)
- `SAP - (Preview) Data Exported from a Production System using a Transport` (SAP Change Requests log)
- `SAP - (Preview) Printing of Potentially Sensitive data` (SAP Spool + Spool Output logs)
**Persistency**
- `SAP - Activation or Deactivation of ICF Service` (SAP Table Data Log)
- `SAP - New ICF Services` (SAP Table Data Log)
- `SAP - (Preview) AS JAVA - User Creates and Uses New User` (SAPJAVAFilesLog)
### Watchlists
- `SAPSystemParameters` (already covered by the `pahi-legacy-reader` extension - just cross-linking for completeness).
### Notes
- Rules that depend on the ABAP Audit Log and ABAP Change Documents Log stay in the official docs because the agentless connector streams both.
- `SAP - New ICF Service Handlers` is Audit Log-based and remains in the official [security content reference](https://learn.microsoft.com/azure/sentinel/sap/sap-solution-security-content).
- Where community versions already exist, please reply with a link so we can cross-reference from the official docs.
Filed as part of the docs cleanup PR: MicrosoftDocs/defender-docs-pr#8934
Beitragsleitfaden
Rechercherichtung
Beginne mit der Prüfung von integration-artifacts/solution-packages/baseline-extension-package und der bestehenden pahi-legacy-reader-Erweiterung. Vergleiche die aufgeführten Kandidaten für analytics-rule und SAPSystemParameters mit etwaigen Community-Versionen und dokumentiere anschließend Links oder den Implementierungsstatus zur Querverweisung. Erledigt ist die Aufgabe, wenn die Kandidaten eindeutig abgedeckt sind oder einen expliziten Status haben.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Bereich
- security
- Issue-Typ
- Feature
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Ruhig
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 45/100