You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|**BTP - Failed access attempts across multiple BAS subaccounts**|Identifies failed Business Application Studio (BAS) access attempts over a predefined number of subaccounts.<br>Default threshold: 3 |||
44
-
|**BTP - Malware detected in BAS dev space**|Identifies instances of malware detected by the SAP internal malware agent within BAS developer spaces. |||
45
-
|**BTP - User added to sensitive privileged role collection**|Identifies identity management actions where a user is added to a set of monitored privileged role collections. |||
46
-
|**BTP - Trust and authorization Identity Provider monitor**|Identifies create, read, update, and delete (CRUD) operations on Identity Provider settings within a subaccount. |
47
-
|**BTP - Mass user deletion in a sub account**|Identifies user account deletion activity where the number of deleted users exceeds a predefined threshold.<br>Default threshold: 10 |||
43
+
|**BTP - Failed access attempts across multiple BAS subaccounts**|Identifies failed Business Application Studio (BAS) access attempts over a predefined number of subaccounts.<br>Default threshold: 3 |Run failed login attempts to BAS over the defined threshold number of subaccounts. <br><br>**Data sources**: SAPBTPAuditLog_CL | Discovery, Reconnaissance|
44
+
|**BTP - Malware detected in BAS dev space**|Identifies instances of malware detected by the SAP internal malware agent within BAS developer spaces. |Copy or create a malware file in a BAS developer space. <br><br>**Data sources**: SAPBTPAuditLog_CL| Execution, Persistence, Resource Development|
45
+
|**BTP - User added to sensitive privileged role collection**|Identifies identity management actions where a user is added to a set of monitored privileged role collections. |Assign one of the following role collections to a user: "Subaccount Service Administrator", "Subaccount Administrator", "Connectivity and Destination Administrator", "Destination Administrator", "Cloud Connector Administrator”. <br><br>**Data sources**: SAPBTPAuditLog_CL | Lateral Movement, Privilege Escalation|
46
+
|**BTP - Trust and authorization Identity Provider monitor**|Identifies create, read, update, and delete (CRUD) operations on Identity Provider settings within a subaccount. | Change, read, update, or delete any of the identity provider settings within a subaccount. <br><br>**Data sources**: SAPBTPAuditLog_CL | Credential Access, Privilege Escalation |
47
+
|**BTP - Mass user deletion in a subaccount**|Identifies user account deletion activity where the number of deleted users exceeds a predefined threshold.<br>Default threshold: 10 |Delete count of user accounts over the defined threshold. <br><br>**Data sources**: SAPBTPAuditLog_CL | Impact|
48
48
49
49
## Next steps
50
50
51
51
In this article, you learned about the security content provided with the Microsoft Sentinel Solution for SAP® BTP.
52
52
53
53
-[Deploy Microsoft Sentinel solution for SAP® BTP](deploy-sap-btp-solution.md)
54
-
-[Microsoft Sentinel Solution for SAP® BTP overview](sap-btp-solution-overview.md)
54
+
-[Microsoft Sentinel Solution for SAP® BTP overview](sap-btp-solution-overview.md)
0 commit comments