Log sources › saas:salesforce
saas:salesforce
Inverted view: what can be detected if this is the log you have. SaaS
5
channels
5
analytics
5
techniques
1
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
API login using access_token without login history |
DC0002 User Account Authentication | AN0528 | 1 |
ConnectedApp OAuth policy change / Login as user |
DC0088 Logon Session Metadata | AN1349 | 1 |
DataExport, RestAPI, Login, ReportExport |
DC0038 Application Log Content | AN1520 | 1 |
GET /services/data/vXX.X/groups |
DC0099 Group Enumeration | AN0697 | 1 |
Login |
DC0002 User Account Authentication | AN0811 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1069.003 Cloud Groups | discovery | 1 | 0 |
| T1199 Trusted Relationship | initial access | 2 | 1 |
| T1213.004 Customer Relationship Management Software | collection | 0 | 0 |
| T1538 Cloud Service Dashboard | discovery | 0 | 0 |
| T1550.001 Application Access Token | lateral movement | 4 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2024-53704 | SonicWall SonicOS | T1199 | Mapped |