- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`Detects large-volume data exfiltration attempts through Salesforce REST API GET requests.
This rule monitors Salesforce REST API events where @evt.name
is RestApi
with @http.method
as GET
targeting query and object endpoints (@uri
containing /services/data/*/query*
or /services/data/*/sobjects*
) that return successful responses. The detection triggers on response sizes over 1MB. Large response sizes indicate potential bulk data extraction, which may represent legitimate reporting activities or malicious data theft. Attackers often use API endpoints to systematically extract large volumes of sensitive data while appearing to perform normal application functions.
{{@usr.id}}
to determine what data was accessed and whether the volume aligns with legitimate business needs.