{
  "Name": "SAP BTP",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/SAPBTP.svg\" width=\"75px\" height=\"75px\">",
  "Description": "SAP Business Technology Platform (BTP) is SAP's platform-as-a-service for building, extending, and integrating SAP and third-party applications. It brings together services such as Cloud Integration (CPI), Cloud Identity Services, Business Application Studio, and Build Work Zone that organizations rely on to run business-critical processes.\n\nThe SAP BTP Solution for Microsoft Sentinel ingests audit and activity events from the SAP BTP Audit Log Service across multiple subaccounts using a codeless data connector, and ships detections, hunting content, and a workbook to help security teams monitor BTP for identity abuse (privileged role changes, mass user deletion, IdP/trust tampering), integration threats (Cloud Integration artifact deployment, security-material and access-policy tampering, JDBC data source changes), developer-workspace risks (malware in BAS dev spaces, failed cross-tenant access), and audit coverage gaps (unaudited custom apps, audit log service unavailability).",
  "WorkbookDescription": [],
  "Workbooks": [
    "/Workbooks/SAPBTPActivity.json"
  ],
  "Analytic Rules": [
    "/Analytic Rules/BTP - Audit log service unavailable.yaml",
    "/Analytic Rules/BTP - Build Work Zone unauthorized access and role tampering.yaml",
    "/Analytic Rules/BTP - Cloud Identity Service application configuration monitor.yaml",
    "/Analytic Rules/BTP - Cloud Integration access policy tampering.yaml",
    "/Analytic Rules/BTP - Cloud Integration artifact deployment.yaml",
    "/Analytic Rules/BTP - Cloud Integration JDBC data source changes.yaml",
    "/Analytic Rules/BTP - Cloud Integration package import or transport.yaml",
    "/Analytic Rules/BTP - Cloud Integration tampering with security material.yaml",
    "/Analytic Rules/BTP - Failed access attempts across multiple BAS subaccounts.yaml",
    "/Analytic Rules/BTP - Malware detected in BAS dev space.yaml",
    "/Analytic Rules/BTP - Mass user deletion in a sub account.yaml",
    "/Analytic Rules/BTP - Mass user deletion in Cloud Identity Service.yaml",
    "/Analytic Rules/BTP - Trust and authorization Identity Provider monitor.yaml",
    "/Analytic Rules/BTP - Unaudited custom app with login-only activity.yaml",
    "/Analytic Rules/BTP - User added to privileged Administrators list.yaml",
    "/Analytic Rules/BTP - User added to sensitive privileged role collection.yaml"
  ],
  "Playbooks": [],
  "PlaybookDescription": [],
  "Parsers": [],
  "SavedSearches": [],
  "Hunting Queries": [],
  "Data Connectors": [
    "/Data Connectors/SAPBTPPollerConnector/SAPBTP_DataConnectorDefinition.json"
  ],
  "Watchlists": [],
  "WatchlistDescription": [],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\SAP BTP",
  "Version": "3.1.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
