---
title: Salesforce previously unseen network for application OAuth token via RestApi
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Salesforce previously unseen network
  for application OAuth token via RestApi
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Salesforce previously unseen network for application OAuth token via RestApi
Classification:attackTactic:[TA0001-initial-access](https://attack.mitre.org/tactics/TA0001)Technique:[T1078-valid-accounts](https://attack.mitre.org/techniques/T1078) 
## Goal{% #goal %}

Detects Salesforce OAuth token authentication from previously unseen network domains using the RestApi.

## Strategy{% #strategy %}

This rule monitors Salesforce RestApi events where `@evt.name` is `RestApi` and `@method` is `GET`. It uses new value detection to identify when an application (`@connected_app_id`) authenticates from a network domain (`@network.client.geoip.as.domain`) that has not been previously observed for that application. OAuth refresh tokens are long-lived credentials that allow applications to maintain access without user interaction, making them attractive targets for attackers who have compromised application credentials or stolen tokens from legitimate applications.

This rule uses the ELF tier of Salesforce logging, which populates the `connected_app_id` field, to determine when a new geographic location is seen with a defined application.

## Triage & Response{% #triage--response %}

- Examine the network domain and geographic location associated with the OAuth token usage for `{{@connected_app_id}}` to determine if it represents a legitimate deployment or suspicious activity.
- Review the application's typical usage patterns and authorized deployment locations to verify if the new network is expected.
- Check if there have been recent changes to the application's infrastructure, deployment, or hosting providers that would explain the new network domain.
- Analyze the timing of the OAuth token usage to identify any correlation with suspicious user activity or potential credential compromise.
- Verify with the application owner or development team whether the OAuth token usage from the new network domain was authorized.

*This detection is based on data from [Drift/Salesforce Security Update](https://trust.salesloft.com/?uid=Drift%2FSalesforce+Security+Update) and [Widespread Data Theft Targets Salesforce Instances via Salesloft Drift](https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift).*
