# SAPMAP - an attacker just got the map of your SAP

> SAPMAP maps attack paths across SAP - from an exposed system through RFC to a business process. How SNOK defends SAP: assessment, pentests, red team…

- Source: https://snok.ai/en/news/blog/sapmap-bloodhound-for-sap/
- Author: Jarosław Zdanowski
- Published: 2026-09-22

---
When a security team looks at an SAP landscape, it sees a list of systems. **SAPMAP** looks at the same thing and sees a route. This publicly available, open-source tool, released under a GPL licence, does for SAP exactly what its authors describe in their own words - "like BloodHound for Active Directory, but for SAP": it does not enumerate individual vulnerabilities, it draws the path - from one exposed system, through trust connections, to the place where your money sits.

**SecurityBridge**, a partner of SNOK, attributes the tool to its Director of Security Research, Joris van de Vis. The code is now open and available to anyone. That shifts not so much the technique as the symmetry: the map that until now was drawn by an expert inside an authorised test is now also held by someone who has no authorisation at all.

**In short:**

**1/** SAPMAP discovers SAP systems on the network, maps RFC connections (the technical channels SAP systems use to talk to one another and pass trust between them) and trust relationships, then renders an interactive graph - from initial entry to full control of a business process,

**2/** the tool ships real, working exploits for known SAP vulnerabilities, including CVE-2025-31324, and covers both on-premises systems and SAP BTP,

**3/** it models business-impact scenarios - from a customer-data breach, through payroll, to the supply chain - showing not "which system fell", but "what you actually lose",

**4/** access is open, but use is permitted only with the system owner's written consent - outside an authorised test it is illegal.

## What BloodHound is, and why the comparison matters

A short explanation, because not everyone works in cybersecurity day to day. BloodHound has been a staple of offensive-security work for years. On a Windows network built on Active Directory, it shows the shortest road from an ordinary employee account to the account that administers the whole domain - not as a list of errors, but as a graph of connections. It changed how companies look at their own network: they stopped asking "which account has too many rights" and started asking "which way does someone travel from any employee to full control". SAPMAP brings exactly that idea into the world of SAP.

## Why this is a BloodHound moment, not another scanner

SAP security scanners have existed for years and do something valuable: they tell you that system X has an open gateway and that role Y is over-privileged. They answer the question "what is wrong". They do not answer the question the attacker asks: "which way do I get from here to the target".

An SAP landscape is not a set of separate systems, it is a web of trust. RFC connections, high-privilege technical accounts, integrations between production and development, bridges to the cloud - each is an edge in a graph. The attacker does not need to break in everywhere. They need one entry point and a road that leads from it. SAPMAP draws that road, and its business scenarios show what waits at the end of it. Not "the production system was compromised", but "the payment to the supplier landed in a different account".

![Attack path across an SAP landscape - from an internet-facing system, through the application layer and an RFC connection, to the production system and payroll](https://snok.ai/images/blog/sapmap-attack-map-en.webp)

That is the difference between a report the board files away and a report the board reads to the end.

We recently wrote that [an AI agent can stand on both sides of an attack](https://snok.ai/en/news/blog/jadepuffer-agentic-ransomware-sap-cve/) and that [the most dangerous thing is often the blind spot no one monitors](https://snok.ai/en/news/blog/sap-data-breach-siem-blind-spot/). SAPMAP is of the same order: it does not add a new vulnerability, it makes visible a road that was always there.

## What it means for defence

There is a simple rule we repeat to clients: control is not measured by how hard the attacker's tools are to obtain. It is measured by whether you walked the same path first. Since the map is public, the only sensible response is to move from "which systems have flaws" to "where does the shortest road to our money run - and do we see it when someone walks it".

At SNOK we do this as an **authorised SAP attack-path assessment**, tying together three layers.

**Path mapping.** We run the same class of tools the attacker now holds inside a controlled lab, against your landscape, under authorised-test conditions. The output is not a list of vulnerabilities, it is a graph: from where, along which edges, to where, and what sits at the end.

**Detection.** SAPMAP visualises the path, and [SecurityBridge](https://snok.ai/en/news/blog/trustbroker-5-1-sso-mfa-sap-without-active-directory/) - the platform we work with - sees that path in real time and raises the alarm. A map without a sensor tells you where the risk is. A sensor without a map tells you something is happening but not where it leads. Only together do they produce a picture you can defend in front of an auditor.

**Red teaming with local AI models.** We run the offensive phase on workstations with unrestricted, local AI models in an isolated environment. This has two consequences that are non-negotiable in this kind of work. First, data from your SAP never leaves the lab - it goes to no external API, because the model runs on site. Second, commercial models refuse to assist with the analysis of working exploits, and exploit analysis is the core of red-team work; a local model without those restrictions lets that work happen without anything leaving the premises. All of it runs under a confidentiality agreement and within our ISO 27001 information-security management system.

## What exactly we do for SAP security

The attack-path assessment is one piece. We build SAP security around two hands that have to work together: an offensive hand that finds the road, and a defensive hand that closes it and watches it.

On the offensive side:

**1/** attack-path assessment - mapping escalation paths across the whole SAP landscape, from an exposed system to a business process,

**2/** [SAP penetration testing](https://snok.ai/en/offer/sap-security/sap-penetration-testing/) - testing systems, RFC interfaces, gateways and integrations, ending in proof of what is possible, not just a list of vulnerabilities,

**3/** red teaming - simulating a real attacker on your landscape, with the offensive phase on local AI models whose data never leaves the lab.

On the defensive side:

**4/** configuration and role hardening - closing what the assessment exposed: gateways, technical accounts, authorisations, trust boundaries between systems,

**5/** [monitoring and detection with SecurityBridge](https://snok.ai/en/offer/sap-security/securitybridge/) - continuous real-time oversight of what happens inside SAP, with alerts on movement along an attack path,

**6/** [patch management and SAP Security Patch Day](https://snok.ai/en/offer/sap-security/sap-security-patch-day/) - from assessing new notes to deploying them, keeping the window between publication and fix as short as possible,

**7/** [secure conversion to SAP S/4HANA and RISE](https://snok.ai/en/offer/sap-security/s4hana-conversion/) - guarding the attack surface during migration, when the landscape is most exposed,

**8/** [audit and compliance](https://snok.ai/en/offer/sap-security/nis2-dora-audit/) - preparing for NIS2, DORA and the ISO 27001 standard, with evidence produced before the auditor asks, not after.

## One question for this week

Not "do we have flaws in SAP", because you do, everyone does. The question is: if someone downloaded the public map today and pointed to the shortest road from your most exposed system to payroll - could you draw that same road first, and see it when someone walks it? If the answer is not a firm yes, that is exactly the conversation worth having, before someone else has it for you.

[Write to us](https://snok.ai/en/contact/) - we will show you what an attack-path assessment looks like on a real SAP landscape.

---

## Sources

- SAPMAP, repository [SecuritySilverbacks/SAPMAP](https://github.com/SecuritySilverbacks/SAPMAP), GPL-3.0 licence (accessed 21 Sep 2026).
- SecurityBridge, SAPMAP press materials and industry coverage (securitybrief.com.au, itbrief), July 2026.
