Skip to content

Commit 8010439

Browse files
committed
Update mde-sap-custom-detection-rules.md
1 parent 2dac0aa commit 8010439

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

defender-endpoint/mde-sap-custom-detection-rules.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,14 @@ The SAP BASIS Team and the Security team should co-develop the solution. The SAP
9393
- `whoami`
9494
- `chmod +x`
9595

96+
7. The security team deploys the rule to non-production environments. The security team monitors detections, and the SAP BASIS team monitors jobs/interfaces for errors.
97+
98+
8. The security team deploys the rule to production environments. The SAP BASIS team should monitor jobs and interfaces, and the security team should monitor any alerts that are generated.
99+
100+
## Additional information
101+
102+
To trace SAPXPG using `sapxpg_trace`, see [SAP documentation: Analyzing Problems with External Commands and Programs](https://help.sap.com/doc/saphelp_snc700_ehp01/7.0.1/en-US/4b/272d0ed1341780e10000000a42189c/content.htm?no_cache=true).
103+
96104

97105

98106

0 commit comments

Comments
 (0)