Sentinel Solution for SAP® BTP

Solution: SAP BTP

SAP BTP Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Microsoft Corporation
Support Tier Microsoft
Support Link https://support.microsoft.com/
Categories domains
Version 3.0.10
Author Microsoft
First Published 2023-04-04
Last Updated 2026-02-02
Solution Folder SAP BTP
Marketplace Azure Marketplace · Popularity: 🔵 Medium (60%)

SAP® Business Technology Platform (BTP) is an infrastructure that allows SAP® customers to build no-code/low-code custom apps integrating to SAP® and third-party applications and datasets in order to achieve better business value by streamlining user's activities and interactions with the organization's business applications.

The BTP Solution for Microsoft Sentinel will collect audits and activity logs from the BTP infrastructure and BTP based apps, and will detect threats, suspicious activities, illegitimate activities, and more.

Contents

Data Connectors

This solution provides 1 data connector(s):

Tables Used

This solution uses 2 table(s):

Table Used By Connectors Used By Content
SAPBTPAuditLog_CL SAP BTP Analytics, Workbooks
Update - Workbooks

Internal Tables

The following 1 table(s) are used internally by this solution's content items:

Table Used By Connectors Used By Content
SecurityAlert - Workbooks

Content Items

This solution includes 16 content item(s):

Content Type Count
Analytic Rules 15
Workbooks 1

Analytic Rules

Name Severity Tactics Tables Used
BTP - Audit log service unavailable High DefenseEvasion SAPBTPAuditLog_CL
BTP - Build Work Zone unauthorized access and role tampering High InitialAccess, Persistence, DefenseEvasion, Impact SAPBTPAuditLog_CL
BTP - Cloud Identity Service application configuration monitor Medium CredentialAccess, PrivilegeEscalation SAPBTPAuditLog_CL
BTP - Cloud Integration JDBC data source changes High CredentialAccess, LateralMovement SAPBTPAuditLog_CL
BTP - Cloud Integration access policy tampering High DefenseEvasion, PrivilegeEscalation SAPBTPAuditLog_CL
BTP - Cloud Integration artifact deployment High Execution, Persistence SAPBTPAuditLog_CL
BTP - Cloud Integration package import or transport Medium InitialAccess, Persistence SAPBTPAuditLog_CL
BTP - Cloud Integration tampering with security material Medium CredentialAccess, DefenseEvasion SAPBTPAuditLog_CL
BTP - Failed access attempts across multiple BAS subaccounts Medium Reconnaissance, Discovery SAPBTPAuditLog_CL
BTP - Malware detected in BAS dev space Medium ResourceDevelopment, Execution, Persistence SAPBTPAuditLog_CL
BTP - Mass user deletion in SAP Cloud Identity Service Medium Impact SAPBTPAuditLog_CL
BTP - Mass user deletion in a sub account Medium Impact SAPBTPAuditLog_CL
BTP - Trust and authorization Identity Provider monitor Medium CredentialAccess, PrivilegeEscalation SAPBTPAuditLog_CL
BTP - User added to Cloud Identity Service privileged Administrators list High LateralMovement, PrivilegeEscalation SAPBTPAuditLog_CL
BTP - User added to sensitive privileged role collection Low LateralMovement, PrivilegeEscalation SAPBTPAuditLog_CL

Workbooks

Name Tables Used
SAPBTPActivity SAPBTPAuditLog_CL
Update
Internal use:
SecurityAlert

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.12 29-12-2025 Updated grid view UI with new subaccount onboarding properties
3.0.11 29-12-2025 Added queryWindowDelayInMin for SAP log delays and included the SAP CIS analytic rules.
3.0.10 03-10-2025 Resolves data connector duplicate handle pagination errors
3.0.9 02-09-2025 Connector UI fix
3.0.8 03-12-2024 Removal of Function App data connector
3.0.7 24-07-2024 Updated BAS malware rule after changes in source message format
3.0.6 23-07-2024 Resolves ContentTemplateNotFound error for CCP
3.0.5 15-07-2024 Remove data source mappings for deprecated function app connector
3.0.4 11-07-2024 Move codeless connector to GA and deprecated function app connector
3.0.3 21-06-2024 Fixes issue with data connector TokenEndpoint query parameter
3.0.2 21-03-2024 Fix data connector version mismatch
3.0.1 19-03-2024 Add data connector based on CCP with support for multiple subaccounts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index