Salesforce Forensics: Telemetry for Detection & Response
ID: 293c1fcb-0687-5d91-8711-5d8ce09e9fa6
STIX ID: report--293c1fcb-0687-5d91-8711-5d8ce09e9fa6
Feed Name: Abstract Security Blog
This report outlines how to investigate and monitor Salesforce for security incidents by leveraging native telemetry sources—Login History, Setup Audit Trail, Event Monitoring, Threat Detection, and Field History Tracking—along with their access tiers, retention limits, and delivery delays. It contextualizes these capabilities against SaaS-focused intrusions (e.g., Salesforce–Drift) and techniques like abusing multiple identity providers for persistence, offering practical guidance for correlating user activity, detecting anomalous data access, and building forensic timelines across Salesforce editions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
