IntrudeGuard

Automated monitoring of SAP cyber security and compliance

A cloud-based solution that watches your SAP landscape continuously — secure configuration, compliance, and security events — so intrusions are caught the moment they happen.

Why it exists

It's all about ensuring the confidentiality, integrity, and availability of SAP systems and data. Traditional tools weren't built to hear what SAP is saying.

Increasing vulnerabilities and attacks

SAP security vulnerabilities are uncovered regularly, many easily exploitable, resulting in more attacks on SAP systems.

Lack of visibility

Monitoring SAP security threats is often cumbersome and sits outside the purview of traditional SIEM and SOC operations.

Inadequate cybersecurity controls

Traditional SAP assessments focus on SoD, passwords, and security auditing — no longer sufficient on their own.

No clear responsibility

In most organizations, no one is explicitly responsible for SAP cybersecurity — IntrudeGuard gives that person a system to own.

Advantages

Built to be dropped into a live SAP landscape without disruption.

Cloud-based

A cloud-based solution for automated monitoring of the SAP landscape.

Automated monitoring

Compliance, secure configuration, and security events — system settings, parameters, patch and release management, technical components (GW/MS), RFC, and more, plus deviating user behavior.

No add-on required

No need to install any add-on and no custom code required.

On-premise and cloud

Covers SAP BTP (global and subaccounts), SAP Cloud Identity Services (IAS/IPS), SAP SuccessFactors, and SAP ABAP.

Any SAP architecture

Compatible with S/4, ECC, BW, SolMan and more — on premise, private cloud, or SAP RISE.

Multiple alerting

ITSM integration, SIEM integration, email, Teams, and more.

Very low effort

Low implementation and maintenance effort, with no downtime required.

Key checks and features

  • Covers all typical IT controls as part of an external financial audit
  • Detects attempts to compromise key system components
  • Flags user and access management attempts by anyone outside the access solution team
  • Watches for deviating user behaviour, including execution of critical activities
  • Surfaces account compromise and account sharing
  • Flags non-compliant changes to secure setup and configuration
  • Detects abnormal data extraction
  • 300+ use cases out of the box

What generic security tools miss

Firewalls, antivirus, and off-the-shelf SIEM weren't built to read SAP's own protocols. These are the patterns they let straight through.

Behavior in the system

Data access

Downloading, displaying, or changing critical tables

Session activity

Logon from several workstations for individual users

Credentials

Password spray attacks, and logons with users like SAP* and DDIC

Interfaces

RFC gateway exploitation attempts, and RFC hopping between connected systems

Privilege

Debugging in production, and assignment of SAP_ALL or SAP_NEW

System behaviour

Profile parameter changes and execution of critical programs or remote function modules

Configuration of the system itself

Patching

Missing critical SAP notes, and outdated DB, kernel, Web Dispatcher, or SAP Router versions

Connections

Insecure connections between SAP systems, and open access control lists around critical components

Secrets

A secure store still running its default encryption key, and old or insecure password hashes

Defaults

Default accounts left with default passwords, and insecure default values across most parameters

Auditability

Inactive logging capabilities that let activity go unrecorded

Change control

A system change option left too open

Want to try? We've got you covered.

One month, free

A free trial for one month with all core features included.

Dedicated support

Dedicated support even during the trial period, not just after you sign.

Free assessment

A free-of-charge SAP security assessment and pentest of your SAP landscape.

See IntrudeGuard on your own landscape

Start free trial