Browse Rules

Search and filter across all detection sources

25 rules

sagan informational other

[SALESFORCE] CredentialStuffingEvent event detected

[SALESFORCE] CredentialStuffingEvent event detected

sagan informational other

[SALESFORCE] PermissionSetEvent event detected

[SALESFORCE] PermissionSetEvent event detected

sagan informational other

[SALESFORCE] Login After Brute Force

[SALESFORCE] Login After Brute Force

sagan informational other

[SALESFORCE] Session Hijacking Event Detected

[SALESFORCE] Session Hijacking Event Detected

sagan medium other

[DYNAMIC] Salesforce logs detected via program.

[DYNAMIC] Salesforce logs detected via program.

sagan informational other

[SALESFORCE] Failed Identity Verification Event Detected

[SALESFORCE] Failed Identity Verification Event Detected

sagan informational other

[SALESFORCE] Login as Org Admin Detected

[SALESFORCE] Login as Org Admin Detected

sagan informational other

[SALESFORCE] Anomalous Export Event Detected - Possible Exfil

[SALESFORCE] Anomalous Export Event Detected - Possible Exfil

panther informational python

Salesforce Admin Login As User

Salesforce detection that alerts when an admin logs in as another user.

sagan informational other

[SALESFORCE] Anomalous API Activity from a User Detected

[SALESFORCE] Anomalous API Activity from a User Detected

sagan informational other

[SALESFORCE] File Action was Blocked for a User

[SALESFORCE] File Action was Blocked for a User

sagan informational other

[SALESFORCE] Suspicious IP Detected via Bluedot - Successful Login

[SALESFORCE] Suspicious IP Detected via Bluedot - Successful Login

sagan informational other

[SALESFORCE] File Policy Violation not Blocked for Exempt User

[SALESFORCE] File Policy Violation not Blocked for Exempt User

sagan informational other

[SALESFORCE] Possible Brute Force Failed Login Attempts [25/1]

[SALESFORCE] Possible Brute Force Failed Login Attempts [25/1]

sublime medium mql

Salesforce infrastructure abuse

Identifies messages that resemble credential theft, originating from Salesforce. Salesforce infrastrcture abuse has been observed recently to send phishing attacks.

panther medium python

Salesforce API Anomaly Detection (RET Passthrough)

Salesforce Real-Time Event Monitoring has detected anomalous API activity. This could indicate compromised credentials, automated abuse, data exfiltration attempts, or other suspicious API usage patterns.

sublime medium mql

Impersonation: Salesforce fake campaign failure notification

Detects messages impersonating Salesforce with urgent language about failed or cancelled campaigns, containing external links from first-time senders outside legitimate Salesforce domains.

panther medium python

Salesforce Bulk API Data Exfiltration

Detects Salesforce Bulk API operations that could indicate data exfiltration attempts. The Bulk API allows users to process large volumes of records (up to millions) asynchronously, making it a common vector for data theft. This detection triggers on all Bulk API job completions and adjusts severity based on: - Operation type (query operations are highest risk for exfiltration) - Volume of records processed - Entity/object type being accessed

sublime low mql

Spam: Personalized subject and greetings via Salesforce Marketing Cloud

Detects messages sent through Salesforce Marketing Cloud infrastructure that contain a fake previous email thread, where both the current and previous threads start with the same greeting pattern extracted from the subject line.

panther medium python

Salesforce OAuth Credential Abuse Detection

Detects OAuth credential abuse and suspicious token usage patterns in Salesforce. OAuth tokens provide API access and can be abused if compromised, making this detection critical for: - Stolen or leaked OAuth tokens - Token replay attacks - Excessive API usage indicating automated abuse - Failed token refresh attempts (potential brute force) - Unauthorized token revocations This detection triggers on OAuth-related security events and adjusts severity based on: - Token revocation events (may ind

panther medium python

Salesforce Third-Party Integration Monitoring

Monitors third-party integrations and OAuth connected apps accessing Salesforce. Connected apps use OAuth for authorization and can access data on behalf of users, making them a potential vector for: - Unauthorized data access - Shadow IT applications - Compromised OAuth tokens - Over-privileged integrations This detection triggers on connected app usage events and adjusts severity based on: - Connection type (refresh tokens are higher risk) - App authorization events - Suspicious app naming pa

sublime medium mql

Google Notification alert link from non-Google sender

This rule detects messages that leverage a link to notifications.google.com not from google and from an untrusted sender. Commonly abused in salesforce phishing campaigns.

sublime high mql

Service Abuse: ExactTarget with suspicious sender indicators

Message originates from ExactTarget infrastructure but uses a suspicious sender domain, including overly long salesforce.com domains, awsapps.com domains, domains containing UTF-8 encoding characters, or a suspicious sender display name.

sublime medium mql

Service abuse: Recruiting with suspicious language patterns from legitimate platforms

Detects suspicious recruiting messages from legitimate services like Salesforce, LADesk, or AWS Apps with unusually long sender email addresses and recruiting-specific language patterns that may indicate abuse of trusted platforms for social engineering.

sigma medium sigma

Activity Performed by Terminated User

Detects when a Microsoft Cloud App Security reported for users whose account were terminated in Azure AD, but still perform activities in other platforms such as AWS or Salesforce. This is especially relevant for users who use another account to manage resources, since these accounts are often not terminated when a user leaves the company.