A guide to threat hunting and monitoring in Snowflake
ID: e787cb0c-89ed-5272-b49d-1a672e317cf3
STIX ID: report--e787cb0c-89ed-5272-b49d-1a672e317cf3
Feed Name: Datadog Security Labs
This guide outlines practical threat-hunting methods for Snowflake environments in response to an emerging campaign targeting Snowflake credentials, providing ready-to-use SQL queries, IOCs (malicious IPs and client identifiers), and clear “what to look for” guidance to detect suspicious logins, unapproved clients (e.g., DBeaver, rapeflake), network policy changes, privilege escalation, OAuth token misuse, brute-force patterns, large data access, and exfiltration via COPY INTO, stages, and anomalous data transfers, along with recommended security best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
