Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

SAP Threat Detection with Microsoft Sentinel & Onapsis

Onapsis
06/14/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In fact, one could say that this year may not serve as a huge wake-up call for CISOs and CIOs worldwide. We have two critical SLP zero-day scenarios that, while patched quickly, will lead to multiple waves of attacks of vulnerable SLP systems at critical infrastructure and large SLP enterprises worldwide. We saw Shiny Hunters not only breach multiple large global organizations, but also release a public SLP exploit in August. And then just one month later, Shiny Hunters used that same exploit to attack and unfortunately cripple operations at one of the world's largest manufacturers, which ended up publicly disclosing $260 million of direct one-time costs related to that cyber incident. In 2025, we're on pace for the largest number of reported SLP vulnerabilities on record. And unfortunately, many of our SLP defenders have faced challenges obtaining, disseminating, and operationalizing good SLP threat insights and exploit detection that would have helped them defend what matters most to their organizations. And that changes today. The new integration between Microsoft's Thinking for SLP solution and Linux's Defend gives security teams exactly what they need to combat and ultimately keep ahead of these targeted and sophisticated attacks. By delivering focused SLP security events, threat insights, and powerful SLP exploit detection directly to the security operations center in the platform that you use every day. Together, Microsoft and Linux are eliminating these SLP security gaps and enabling faster, smarter incident response. This partnership unites Microsoft Sentinel's best-in-class correlation engine and powerful security co-pilot AI with Enapsis's unmatched threat coverage, which includes the world's largest dedicated knowledge base of SAP threat rules, SAP-focused insights from the world-renowned Enapsis Research Labs, and exclusive access to zero-data rules that can protect your critical systems before SAP patches are even made available. Together, we're empowering our customers to accelerate SAP threat detection and response, vastly reduce the risk from SAP security incidents, and defend the critical systems from the threat actors and ransomware groups that are attacking enterprises worldwide. You'll see now in the demo next, like a sample of an adversary in the middle attack, where we actually run a multi-factor authentication bypass, which then reflects on the Sentinel site. We correlate what Enapsis Defend provides them as evidence from the SAP backend, and everything that Microsoft can do through our Sentinel for SAP offering is then enriched from there. So let's roll from there so that we can see this in action. So on the left, we have the victim screen, and on the right, the hacker in parallel. So imagine they are on different machines, and phishing email campaigns are still a thing. So you see there a weaponized email link where the user tries to log in, provides all their credentials, gets the typical MFA pop-up, fills in the numbers, and the hacker is already there sitting, waiting, because non-phish-resistant MFA can be bypassed through this. And we see here the hacker is seeing the session cookie for the multi-factor authentication bypass attack, and is now able to use the recorded cookie that the victim provided in a different country, different place, and use it either through an already compromised network where you have access to internal resources, and you see the session cookie here giving you access to the Fiori launchpad. For the purpose of this demo, we also added here the capability to run the transaction that gives you voice access. So now we switch over to the SOC team. Let's see this consolidated view of the attack timeline, everything that Sentinel already has, which ranges from the phishing link click and outlook, and the user reporting that they found this a bit funky, how the screen worked, adding another signal there, and EntroID giving us the MFA risky user state also. And there on the right, we see security copilot reasoning over this. We have on-office defend being mentioned as one of the signals, so that the summary already on this attack incident shows you all the steps were taken, where the signals came from, and of course the ability to contain from here the device, the user, run SAP user blocks, password reset, et cetera. And this is then presented back on, for instance, for teams to the SAP security team or the SOC team, providing the evidence on what's happening and if you want to take action. Block the SAP user from here with the human in the middle so that you can make conscious actions on this rather than fully automatic. Then everything you put in here as a comment is then fed back into Sentinel so that you have a complete trail on reasoning why and who did execute this action. And it's very simple to install. Just go to Sentinel Constant Hub, find your Napsos Defend entry there, go browse for it, check the installation prerequisites, and hit the deploy button, which gives you all the things needed as the receiver on the end on the Sentinel side, and the information down below to fed back to your Napsos Defend installation to actually finalize the integration. It's a push-based mechanism, so you just bring in the information back to Defend, configure there, click submit, and it starts sending to all Sentinel.

TL;DR

  • 2025 has seen unprecedented SAP security incidents, including zero-day exploits and the Shiny Hunters breach that cost one manufacturer $260 million, highlighting critical gaps in traditional SAP security monitoring.
  • The Microsoft Sentinel for SAP and Onapsis Defend integration delivers SAP-specific threat intelligence and exploit detection directly to SOC teams, combining Sentinel's AI-powered correlation with Onapsis's specialized SAP threat knowledge base.
  • Live demonstration shows detection and response to an adversary-in-the-middle attack with MFA bypass, illustrating how Security Copilot AI and automated playbooks enable rapid containment of SAP threats through a unified console.

Summary

This demonstration showcases the integration between Microsoft Sentinel for SAP and Onapsis Defend, addressing critical gaps in SAP security monitoring. The presentation opens with context on 2025's escalating SAP threat landscape, including zero-day exploits, the Shiny Hunters breach resulting in $260 million in damages, and record-breaking vulnerability disclosures. The demo illustrates how the partnership delivers SAP-specific threat intelligence directly to security operations centers, combining Microsoft Sentinel's correlation engine and Security Copilot AI with Onapsis's specialized SAP threat detection capabilities. A live adversary-in-the-middle attack demonstration shows MFA bypass and session hijacking, followed by how the integrated platform enables rapid incident response through automated playbooks and AI-assisted analysis. The presentation concludes with a walkthrough of the simple deployment process via Sentinel Content Hub, emphasizing the solution's ability to eliminate SAP blind spots and bridge the gap between SAP Basis teams and SOC operations.

Chapters

0:00 - SAP Security Threat Landscape 2025
1:16 - Microsoft Sentinel & Onapsis Integration
2:35 - Adversary-in-the-Middle Attack Demo
4:10 - SOC Response & Security Copilot
5:34 - Deployment & Configuration Walkthrough

Key Quotes

0:45 "Shiny Hunters used that same exploit to attack and unfortunately cripple operations at one of the world's largest manufacturers, which ended up publicly disclosing $260 million of direct one-time costs related to that cyber incident."
1:39 "Together, Microsoft and Linux are eliminating these SLP security gaps and enabling faster, smarter incident response."
2:03 "... exclusive access to zero-data rules that can protect your critical systems before SAP patches are even made available."

FAQ

How does the Onapsis Defend integration improve SAP security visibility in Microsoft Sentinel?

The integration feeds high-fidelity SAP threat intelligence and exploit detection directly into Microsoft Sentinel, providing SOC teams with visibility into the SAP application layer that traditional SIEMs typically miss. This includes access to Onapsis's specialized SAP threat rules, zero-day detection capabilities, and consolidated attack timelines that correlate SAP-specific events with broader enterprise security signals.

What makes this solution effective against sophisticated SAP attacks like the ones demonstrated?

The solution combines Microsoft Sentinel's correlation engine and Security Copilot AI with Onapsis's deep SAP security expertise, including the world's largest SAP threat rule knowledge base and zero-day detection rules from Onapsis Research Labs. This enables detection of complex attack chains like adversary-in-the-middle with MFA bypass, automated incident response through playbooks, and AI-assisted analysis that helps SOC analysts contain threats in minutes rather than days.


Categories:
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Security Operations
  • Threat Intelligence
  • Demo
  • Technical Deep Dive
  • SAP Security
  • SIEM Integration
  • Threat Detection
  • Incident Response
  • Zero-Day Protection
  • MFA Bypass
  • Security Copilot AI
  • SOC Operations
  • Enterprise Risk Management
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: SAP Threat Detection with Microsoft Sentinel & Onapsis

              Upcoming Webinar Calendar

              • 06/17/2026
                12:00 PM
                06/17/2026
                Action1: The Remediation Gap: Vulnerability Management in the Age of AI
                https://www.truthinit.com/index.php/channel/2010/action1-the-remediation-gap-vulnerability-management-in-the-age-of-ai/
              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats When the Cloud Faces Challenges
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/

              Upcoming Events

              • Jun
                17

                Action1: The Remediation Gap: Vulnerability Management in the Age of AI

                06/17/202612:00 PM ET
                • Jun
                  23

                  The AI-Powered VMware Alternative

                  06/23/202601:00 PM ET
                  • Jun
                    24

                    LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                    06/24/202611:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version