Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0550 — Detecting Suspicious Access to CRM Data in SaaS Environments
DET0550

Detecting Suspicious Access to CRM Data in SaaS Environments

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1520 Analytic 1520
SaaS

Anomalous high-volume access to customer records in CRM software by a non-CRM admin user account, especially following initial authentication from a rare location or device. Behavior includes abnormal access to PII fields or data exports within a short time window.

saas:salesforce DataExport, RestAPI, Login, ReportExport m365:signinlogs UserLoggedIn
[TimeWindow] Duration over which bulk CRM queries occur (e.g., 1 minute, 5 minutes); varies by organization usage pattern
[UserContext] User's CRM role, department, or job function (e.g., non-sales user accessing customer PII)
[AnomalousExportThreshold] Number of CRM objects (contacts, deals, logs) accessed or exported above normal
[SourceLocation] Rare or impossible geolocation/IP address for legitimate CRM user access

Detected Techniques

1

Details

MITRE ID
DET0550
STIX ID
x-mitre-detection-strategy--34fb7d2b-f5be-45a2-9cdc-811ae843e379
Analytics
1
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.