Pathlock TDnR - Authorization Check Value Changes (SU24)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects changes to authorization check values in the SU24 table in SAP, forwarded by Pathlock Threat Detection and Response. SU24 defines which authorization objects are checked for each transaction; unauthorized changes can effectively disable authorization checks and allow privilege escalation without modifying roles or profiles.

Attribute Value
Type Analytic Rule
Solution Pathlock_TDnR
ID 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c62
Severity High
Status Available
Kind Scheduled
Tactics DefenseEvasion, PrivilegeEscalation
Techniques T1562, T1548
Required Connectors Pathlock_TDnR
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Pathlock_TDnR_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Pathlock_TDnR