The Sound of Silence: SAP SM49/SM69 and the OS Commands Your SIEM Never Hears
Brief
The audit blind spot in external OS command execution
Responsible-research note. Everything below was performed on a self-owned SAP lab. No third-party or production system was involved. The purpose is defensive: to show exactly where SAP does, and does not, record operating-system command execution, and to give blue teams working detections and remediation.
The audit-log screenshots have been redacted to remove the workstation account name and local file paths; the remaining identifiers ( vhcalnplci, NPL, npladm) are the public defaults of the free SAP Developer Edition and carry no sensitive information. No IP addresses, credentials, or license keys appear anywhere in this article. Why I went looking
Every SAP hardening checklist says the same thing about external operating-system commands: restrict S_LOG_COM and S_RZL_ADM, and review your SM69 command list. Good advice.
