Detection rules › YARA-L

sap sensitive tables direct access by rfc logon static list

Severity
high
Time window
1h
Match by
table
Author
Google Cloud Security
Source
github.com/chronicle/detection-rules

Detects direct access to highly sensitive SAP tables (USR02, PAYR, P0002) via RFC logon. This specifically monitors for potential theft of user hashes (USR02), payroll data (PAYR), or personal employee information (P0002).

MITRE ATT&CK coverage

TacticTechniques
Collection

Rule body

// Copyright 2026 Google LLC. Licensed under Apache-2.0.

rule sap_sensitive_tables_direct_access_by_rfc_logon_static_list {

  meta:
    author = "Google Cloud Security"
    description = "Detects direct access to highly sensitive SAP tables (USR02, PAYR, P0002) via RFC logon. This specifically monitors for potential theft of user hashes (USR02), payroll data (PAYR), or personal employee information (P0002)."
    severity = "High"
    tactic = "TA0009"
    technique = "T1005"
    log_source = "SAP_SECURITY_AUDIT"

  events:
    $e.metadata.log_type = "SAP_SECURITY_AUDIT"
    $e.additional.fields["msg_1"] = "CUZ"

    $sid = $e.target.application
    $table = $e.additional.fields["param1_1"]

    $table = /USR02|PAYR|P0002/

  match:
    $table over 1h

  outcome:
    $user_list = array_distinct($e.principal.user.userid)
    $source_ips = array_distinct($e.principal.ip)
    $system_ids = array_distinct($sid)
    $event_count = count($e.metadata.id)
    $terminal_names = array_distinct($e.principal.hostname)
    $client_ids = array_distinct($e.target.resource.attribute.labels["slgmand_1"])

  condition:
    $e
}

YARA-L rule structure

Condition

Fires when at least one $e event in the 1h window.

Events

$e

  • metadata.log_type = "SAP_SECURITY_AUDIT"
  • additional.fields["msg_1"] = "CUZ"
  • additional.fields["param1_1"] matches "USR02|PAYR|P0002"

Match and correlation

Match key
$table
Within
1h

Outcome

Outcome variables add context to a detection. When the rule generates an alert, $risk_score is displayed with it.

FieldExpression
user_listarray_distinct($e.principal.user.userid)
source_ipsarray_distinct($e.principal.ip)
system_idsarray_distinct($sid)
event_countcount($e.metadata.id)
terminal_namesarray_distinct($e.principal.hostname)
client_idsarray_distinct($e.target.resource.attribute.labels["slgmand_1"])