Snowflake
Telemetry Evidence
These values show how indexed rules identify Snowflake telemetry.Kusto
Snowflake Panther
Snowflake.DataTransferHistory Snowflake.GrantsToRoles Snowflake.GrantsToUsers Snowflake.LoginHistory Snowflake.QueryHistory snowflake panther_logs.public.snowflake_queryhistory panther_logs.public.snowflake_sessions snowflake.account_usage.data_transfer_history snowflake.account_usage.grants_to_users snowflake.account_usage.login_history snowflake.account_usage.query_history SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY snowflake.account_usage.sessions snowflake.account_usage.users
Detection Rules
Kusto #
- Snowflake - Abnormal query process time source medium: 'Detects query with abnormal proccess time.'
T1499 - Snowflake - Multiple failed queries source high: 'Detects multiple failed queries in short timeframe.'
T1082,T1518 - Snowflake - Multiple login failures by user source high: 'Detects multiple login failures by user.'
T1078 - Snowflake - Multiple login failures from single IP source high: 'Detects Mmltiple login failures from single IP.'
T1078 - Snowflake - Possible data destraction source medium: 'Detects possible data destruction.'
T1485 - Snowflake - Possible discovery activity source medium: 'Detects possible discovery activity.'
T1526 - Snowflake - Possible privileges discovery activity source medium: 'Detects possible privileges discovery activity.'
T1087 - Snowflake - Query on sensitive or restricted table source medium: 'Detects query on sensitive or restricted table.'
T1119 - Snowflake - Unusual query source medium: 'Detects unusual query.'
T1119 - Snowflake - User granted admin privileges source medium: 'Detects when user asigned admin privileges.'
T1078
Panther #
- Query.Snowflake.AccountAdminGranted source: Monitor and detect granting account admin role.
- Query.Snowflake.BruteForceByIp source: Detect brute force attempts by monitoring for failed logins to snowflake.
- Query.Snowflake.BruteForceByUsername source: Detect brute force attempts by monitoring for failed logins to snowflake.
- Query.Snowflake.ClientIp source: Monitor for malicious IPs interacting with Snowflake as part of ongoing cyber threat activity reported May 31st, 2024
- Query.Snowflake.CopyIntoStage source: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion/
- Query.Snowflake.External.Shares source: Monitor for external shares from one cloud source to another.
- Query.Snowflake.FileDownloaded source: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion/
- Query.Snowflake.KeyUserPasswordLogin source: Detects when a user with a configured RSA key logs in with a password
- Query.Snowflake.MFALogin source: Monitor logins that are not using MFA.
- Query.Snowflake.Multiple.Logins.Followed.By.Success source: Monitor for brute force user activity.
Show 21 more
- Query.Snowflake.SuspectedUserAccess source: Return sessions of suspected clients as part of ongoing cyber threat activity reported May 31st, 2024
- Query.Snowflake.TempStageCreated source: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion/
- Query.Snowflake.ThreatHunting.ClientIp source: Monitor for malicious IPs interacting with Snowflake as part of ongoing cyber threat activity reported May 31st, 2024
- Query.Snowflake.ThreatHunting.SuspectedUserAccess source: Return sessions of suspected clients as part of ongoing cyber threat activity reported May 31st, 2024
- Query.Snowflake.UserCreated source: Monitor for new users.
- Query.Snowflake.UserEnabled source: Monitor for users that are being re-enabled.
- Snowflake Account Admin Granted source medium: Detect when account admin is granted.
T1078 - Snowflake Brute Force Attacks by IP source medium: Detect brute force attacks by monitorign failed logins from the same IP address
T1110 - Snowflake Brute Force Attacks by User source medium: Detect brute force attacks by monitorign failed logins from the same IP address
T1110 - Snowflake External Data Share source medium: Detect when an external share has been initiated from one source cloud to another target cloud.
T1537 - Snowflake File Downloaded source informational: A file was downloaded from a stage.
T1041 - Snowflake Grant to Public Role source medium: Detect additional grants to the public role.
T1078.001 - Snowflake Login Without MFA source medium: Detect Snowflake logins without multifactor authentication
T1556 - Snowflake Password Spray source medium: Detects password spraying attacks against Snowflake by tracking the number of distinct user accounts targeted by failed login attempts from the same source IP address within a short timeframe. Unlike brute force against a single account, password spraying distributes attempts across many accounts to evade lockout policies. This rule complements Snowflake.Stream.BruteForceByIp (same IP, any accounts) and Snowflake.PotentialBruteForceSuccess.Group (brute force followed by confirmed login).
T1110.003 - Snowflake Successful Login source informational: Track successful login signals for correlation.
- Snowflake Table Copied Into Stage source informational: A table was copied into a stage.
T1041 - Snowflake Temporary Stage Created source informational: A temporary stage was created.
T1041 - Snowflake User Created source informational: Detect new users created in Snowflake.
T1136 - Snowflake User Daily Query Volume Spike source: Returns instances where a user's cumulative daily query volume is much larger than normal. Could indicate exfiltration attempts.
- Snowflake User Enabled source informational: Detects users being re-enabled in your environment.
T1136 - Suspicious Snowflake Sessions - Unusual Application source: This query can be used for the detection of unusual, non-common applications and client characteristics that had been used to connect to the Snowflake account, using a comparison to the previous usage baseline.
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Panther #
Package-Only Rules
These rules appear in a Snowflake source package, but their queries do not identify Snowflake telemetry. They do not count toward Rules.Panther #
T1078T1110T1110T1041T1556T1041T1041T1136T1567T1136T1098T1078.004