Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion rules/community/sap/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -128,4 +128,10 @@ credentials, or PII.
| Category | Requirement |
| :--- | :--- |
| **Case Sensitivity** | All entries must be in **UPPERCASE**. SAP logs store User IDs, Roles, and Programs in uppercase; lowercase entries will result in missed detections. |
| **Maintenance** | Lists should be reviewed quarterly or following any major SAP transport cycle where new `Z` programs or roles are introduced. |
| **Maintenance** | Lists should be reviewed quarterly or following any major SAP transport cycle where new `Z` programs or roles are introduced. |

[!WARNING]
**Test Before Deploying:** These SAP community detection rules serve as
foundational templates. Because every SAP environment is unique, you should
thoroughly test all rules against historical data and modify their logic as
needed to match your specific logging structures and security use cases.