Pathlock TDnR - Dynamic Access Control Events

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects events from Pathlock Dynamic Access Control (DAC) for SAP, forwarded to Microsoft Sentinel. DAC events capture real-time access policy decisions and violations, including blocked transactions, emergency access grants, and policy bypass attempts that require immediate investigation.

Attribute Value
Type Analytic Rule
Solution Pathlock_TDnR
ID 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c40
Severity High
Status Available
Kind Scheduled
Tactics PrivilegeEscalation
Techniques T1548, T1134
Required Connectors Pathlock_TDnR
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Pathlock_TDnR_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Pathlock_TDnR