Azure-Sentinel/Solutions/SAP/ReleaseNotes.md

2.5 KiB
Исходник Ответственный История

Solution Releases

Date issued Version Number Content
28/06/23 2.0.74 SAP Audit Control Workbook
18/09/23 2.0.76 SAP Audit Control Workbook
Reflect alerts in addition to incidents
Added visualizations for better monitoring
Focus on SAP alerts by default
Exclude users using wildcards- The SAPUsersGetVIP function now supports excluding users using wildcards. For examples, can exclude all firefighters using FF*.
The “SAP - Security Audit Log Configuration Change” logic was modified so it will not alert on dummy changes that surface after system restart
01/01/2024 3.0.1 Content migrated to a content hub V3 protocol- to overcome the error of “Creating the resource of type Microsoft.Resources/templateSpecs would exceed the quota of 800 resources of type Microsoft.Resources/templateSpecs per resource group”
02/02/2024 3.0.3 Updated and improved logic for these alert rules:
SAP - Execution of an Obsolete or an Insecure Function Module
SAP - Multiple Password Changes
SAP - Assignment of a sensitive role
SAP - Sensitive User's Password Change and Log in
SAP - Login from unexpected network
SAP - Sensitive privileged user makes a change in another user
Updated parsers:
SAPChangeDocsLog- support for blank workspaces, added SystemGuid
SAPJAVAFilesLogs- switch to SAPControl file-based logs
SAPSpoolLog, SAPSpoolOutputLog- handle different SpoolRequestNumber formats in different SAP releases
SAPTableDataLog- handle SidGuid, UpdatedOn fields
SAPUsersAssignments- inffer user master data changes in near realtime
SAPUsersGetPrivileged- allow SAP AS JAVA systems support
06/03/2024 3.1.0 New JAVA AS alert rules
SAP - (Preview) AS JAVA - Sensitive Privileged User Signed In
SAP - (Preview) AS JAVA - Sign-In from Unexpected Network
SAP - (Preview) AS JAVA - User Creates and Uses New User
SAP - Execution of an Obsolete or an Insecure Function Module- improved logic
15/04/2024 3.1.4 Bug fixes
25/04/2024 3.1.5 Fixes SAPCONTROL_CL error when using cross workspace feature
16/06/2024 3.1.7 Improved and simplified logic for 4 alert rules:
SAP Data has Changed During Debugging Activity
SAP Execution of Sensitive Function Module
SAP Function module tested
SAP Multiple Logons by IP.

Fixed bugs in parsers:
SAPCRLog, SAPGetSystemParameter.

Added additionalData column to "SAP - Systems" watchlist