{
  "Name": "Pathlock_TDnR",
  "Author": "Pathlock Inc. - support@pathlock.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/pathlock_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Pathlock TD&R](https://pathlock.com/products/cybersecurity-application-controls/) integration enables organizations to seamlessly forward Pathlock Threat Detection and Response (TD&R) events from both on-premise and cloud-based SAP systems into Microsoft Sentinel Solution for SAP for unified security visibility and incident correlation across the enterprise.\n\nBuilt on Pathlock’s Cybersecurity Application Controls (CAC) platform, this connector utilizes the Common Connector Platform (CCP) framework to securely transmit log and event data while maintaining data integrity and governance. The Custom Logs solution is automatically deployed during installation, ensuring a quick and reliable setup without manual configuration steps.\n\nWith this integration, SOC and SAP security teams can:\n- Consolidate SAP-specific threat intelligence and correlate it with enterprise events in Microsoft Sentinel.\n- Leverage 4,000+ Pathlock detection signatures and 80+ SAP log sources for comprehensive SAP monitoring.\n- Automate alerting and response workflows in Microsoft Sentinel for faster mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR).\n- Maintain audit readiness by demonstrating end-to-end visibility of SAP threat activity.\n\nThis out-of-the-box connector simplifies secure event forwarding from SAP to Microsoft Sentinel—enabling centralized analysis, compliance reporting, and proactive response within your existing security ecosystem.",
  "Workbooks": [],
  "Analytic Rules": [
    "Analytic Rules/Pathlock_TDnR_ABAP_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_ABAP_DUMPS.yaml",
    "Analytic Rules/Pathlock_TDnR_AUTH_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_BATCH_JOBS.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_BANK.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_BUPA_BANK.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_CCARD.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_DEBI.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_GENERIC.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_GRAC.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_IBAN.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_KERBEROS.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_KRED.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_PAYRQ.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_SACH.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_SECURITY_P.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_USER_CUA.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_USOBT_C.yaml",
    "Analytic Rules/Pathlock_TDnR_CHANGEDOC_USOBX_C.yaml",
    "Analytic Rules/Pathlock_TDnR_CLIENT_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_CLOUD_ACCOUNT_LOGS.yaml",
    "Analytic Rules/Pathlock_TDnR_CLOUD_FOUNDRY_LOGS.yaml",
    "Analytic Rules/Pathlock_TDnR_DBACOCKPIT.yaml",
    "Analytic Rules/Pathlock_TDnR_FILE_CHECKSUM.yaml",
    "Analytic Rules/Pathlock_TDnR_FUNCTION_MODULE_TEST.yaml",
    "Analytic Rules/Pathlock_TDnR_GATEWAY_LOG.yaml",
    "Analytic Rules/Pathlock_TDnR_HANA_AUDIT_TRAIL.yaml",
    "Analytic Rules/Pathlock_TDnR_HANA_DBCON_CONNECT.yaml",
    "Analytic Rules/Pathlock_TDnR_HANA_PARAM_CHANGED.yaml",
    "Analytic Rules/Pathlock_TDnR_HR_PA_CHANGELOG.yaml",
    "Analytic Rules/Pathlock_TDnR_HTTP_LOG.yaml",
    "Analytic Rules/Pathlock_TDnR_ICF_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_ICM_SECURITY_LOG.yaml",
    "Analytic Rules/Pathlock_TDnR_INTERNAL.yaml",
    "Analytic Rules/Pathlock_TDnR_J2EE_SECURITY_LOG.yaml",
    "Analytic Rules/Pathlock_TDnR_J2EE_SEC_AUD_LOG.yaml",
    "Analytic Rules/Pathlock_TDnR_MISSING_OSS_NOTES.yaml",
    "Analytic Rules/Pathlock_TDnR_OS_CMD_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_OUTBOUND_SMTP_MAIL.yaml",
    "Analytic Rules/Pathlock_TDnR_PATHLOCK_DAC.yaml",
    "Analytic Rules/Pathlock_TDnR_PROFILE_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_PSE_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_RAL_AUDIT.yaml",
    "Analytic Rules/Pathlock_TDnR_RAL_DATA.yaml",
    "Analytic Rules/Pathlock_TDnR_RFC_DESTINATIONS.yaml",
    "Analytic Rules/Pathlock_TDnR_ROLE_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_SACF_CHANGES_DESIGN.yaml",
    "Analytic Rules/Pathlock_TDnR_SACF_CHANGES_RUNTIME.yaml",
    "Analytic Rules/Pathlock_TDnR_SAPROUTER.yaml",
    "Analytic Rules/Pathlock_TDnR_SAST_AT.yaml",
    "Analytic Rules/Pathlock_TDnR_SAST_DO.yaml",
    "Analytic Rules/Pathlock_TDnR_SAST_RT.yaml",
    "Analytic Rules/Pathlock_TDnR_SAST_UAM_PWR.yaml",
    "Analytic Rules/Pathlock_TDnR_SCC_LOGS.yaml",
    "Analytic Rules/Pathlock_TDnR_SE16N_CHANGEDOCS.yaml",
    "Analytic Rules/Pathlock_TDnR_SECURITY_AUDIT_LOG.yaml",
    "Analytic Rules/Pathlock_TDnR_SEC_AUDIT_LOG_CLOUD.yaml",
    "Analytic Rules/Pathlock_TDnR_SLG1_LDAPSYNC.yaml",
    "Analytic Rules/Pathlock_TDnR_SLG1_ODATA.yaml",
    "Analytic Rules/Pathlock_TDnR_SPOOL_OUTPUT_REQUEST.yaml",
    "Analytic Rules/Pathlock_TDnR_SPOOL_REQUEST.yaml",
    "Analytic Rules/Pathlock_TDnR_SU24_CHANGELOG.yaml",
    "Analytic Rules/Pathlock_TDnR_SYSLOG.yaml",
    "Analytic Rules/Pathlock_TDnR_SYSPROFILE_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_SYSTEM_CHANGELOG.yaml",
    "Analytic Rules/Pathlock_TDnR_SYSTEM_JOBS.yaml",
    "Analytic Rules/Pathlock_TDnR_TABLE_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_TABLE_SETTINGS.yaml",
    "Analytic Rules/Pathlock_TDnR_TABLE_UTILITY.yaml",
    "Analytic Rules/Pathlock_TDnR_TCODE_STATISTIC.yaml",
    "Analytic Rules/Pathlock_TDnR_TRANSPORT_LOG.yaml",
    "Analytic Rules/Pathlock_TDnR_USER_AUTH_BUFFER.yaml",
    "Analytic Rules/Pathlock_TDnR_USER_LOGINS.yaml",
    "Analytic Rules/Pathlock_TDnR_USER_MASTER_CHANGES.yaml",
    "Analytic Rules/Pathlock_TDnR_USER_PROFILES.yaml",
    "Analytic Rules/Pathlock_TDnR_USER_ROLES.yaml",
    "Analytic Rules/Pathlock_TDnR_WD_HTTP_LOG.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/Pathlock_TDnR_PUSH_CCP/Pathlock_TDnR_connectorDefinition.json"
  ],
  "BasePath": "C:\\Github\\Azure-Sentinel\\Solutions\\Pathlock_TDnR",
  "Version": "3.0.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
