For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-pgq.md. A documentation index is available at /llms.txt.

Twilio bulk export from unusual location

Goal

Detect when a BulkExport operation was detected from unsual location.

Strategy

This rule monitors for BulkExport API calls from unusual location. This may indicate an attacker gaining access to sensitive inforamtion and exfiltrating data.

Triage and response

  1. Investigate the other actions performed by the account SID {{@account_sid}}.
  2. Follow the guidelines provided by Twilio.