<  Back to rules search

Anomalous amount of Salesforce query results

salesforce

Classification:

attack

Tactic:

Set up the salesforce integration.

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when there is a spike in Salesforce query results for a user. A large query can be an early warning sign of a user attempting to exfiltrate Salesforce data.

Strategy

Inspect and baseline Salesforce logs and determine if there is a spike in the number of rows returned (@rows_returned).

Triage and response

  1. Determine if the user should be legitimately performing large queries.