Salesforce login from disabled account

Set up the salesforce integration.

Goal

Detect when a disabled account attempts to log into Salesforce

Strategy

Inspect Salesforce logs and determine if there is a login attempt (@evt.name:LoginEvent) from from a disabled account (@status:\"User is Inactive\"). If more than ten attempts to authenticate to a disabled account a MEDIUM severity signal is created.

Triage and response

Determine if the IP (@network.client.ip) has attempted to log into other accounts.