logo

A guide to threat hunting and monitoring in Snowflake

ID: e787cb0c-89ed-5272-b49d-1a672e317cf3

STIX ID: report--e787cb0c-89ed-5272-b49d-1a672e317cf3

Feed Name: Datadog Security Labs

Date Published: 2024-06-07

Date Updated: 2026-04-27

...
...

This guide outlines practical threat-hunting methods for Snowflake environments in response to an emerging campaign targeting Snowflake credentials, providing ready-to-use SQL queries, IOCs (malicious IPs and client identifiers), and clear “what to look for” guidance to detect suspicious logins, unapproved clients (e.g., DBeaver, rapeflake), network policy changes, privilege escalation, OAuth token misuse, brute-force patterns, large data access, and exfiltration via COPY INTO, stages, and anomalous data transfers, along with recommended security best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.