Read-only demo — configuration is locked. A licensed workspace unlocks every control below.
General Workspace identity, residency and display preferences.
Organisation
Organisation name Confidential · KSA Tier-1 Client
Time zone Arabia Standard Time · GMT+3
Display
Compact table densityTighten rows in the referential grid
Show CVSS vectors inlineRender the full AV/AC string on each record
Highlight actively exploited (KEV)Accentuate in-the-wild vulnerabilities
Data connectors Telemetry and SAP system integrations feeding the correlation engine.
Log & SIEM sources
ELK
Elasticsearch / Logstash Ingesting · 14 pipelines
Connected Configure
ETD
SAP Enterprise Threat Detection Streaming security audit log
Connected Configure
SPL
Splunk HEC HTTP event collector
Token expiring Configure
SNT
Microsoft Sentinel Not configured
Disconnected Connect
SAP system connectors
RFC
NetWeaver RFC / gateway SM59 · config & SAL pull
Connected Configure
HDB
HANA SQL Privilege & audit views
Read-only user Configure
SF
SuccessFactors OData Audit & login API
Connected Configure
BTP
BTP Audit Log service xsuaa · role collections
Connected Configure
Referential How the counter-intelligence dataset stays current and enriched.
Update schedule
Automatic refreshPull new signatures on a schedule
Cadence Weekly · aligned to SAP Patch Day (Tuesday)
Intelligence sources NVD · CISA KEV · EPSS · OSV · SAP security notes
Enrichment
EPSS exploit-probability scoringAttach daily EPSS values
CISA KEV cross-referenceFlag in-the-wild exploitation
Auto-map to assessment domainsAssign AD-01…AD-15 on ingest
Regulatory crosswalkNCA · PDPL · SAMA · ISO · NIST
Detection engine Correlation, alerting and response behaviour of the SAPGUARD LRM.
Correlation
Auto-deploy new detection rulesPush published Sigma content to connected SIEM
Minimum severity to alert
MITRE ATT&CK mappingTag every detection with tactics
Response
Create alert on matchRaise a case in the SOC queue
Alert destination SOC queue · ServiceNow SIR
Suppress reviewed false positivesLearn from analyst dispositions
Notifications Where posture changes and alerts are delivered.
Channels
@
Email digest soc@client · lead assessor
MT
Microsoft Teams #sap-security channel
SMS
SMS escalation Critical only · on-call
Cadence
Immediate alert on new KEV matchBypass the digest for exploited CVEs
Access & roles Members with access to this workspace.
Members Invite member
Member Role Status
KA Engagement ownerOwner Active
LA Lead assessor · The LabAdmin Active
SA SOC analystMember Active
AU External auditorViewer Invited
Security
Enforce single sign-on (SSO)SAML via the client identity provider
Require multi-factor authenticationAll members
Session timeout · 30 minutesIdle sign-out
API keys Programmatic access to the referential and detection content.
Active keys Generate key
Production sk_live_••••••••••••4a2f
600 / min Reveal
Reporting · read-only sk_ro_••••••••••••91c3
120 / min Reveal
CI · detection export sk_ci_••••••••••••e07b
Revoked Reveal
Access scope
Read referentialQuery signatures and mappings
Export detection contentPull Sigma rules
Write / mutate recordsDisabled for all keys