Snowflake UI login via password from proxy or vpn
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect a user account login using a password for authentication directly into the Snowflake UI from a proxy or VPN service.
Strategy
This rule allows you to detect when an account uses a password to login to the Snowflake UI from a proxy or VPN service.
Triage and response
- Inspect the logs to identify the user or service account and associated IP address.
- Review the IP address against other logs associated with that user.
- Investigate whether that user has MFA enabled.
- If the IP address has not been observed in the past and MFA is not enabled, disable the user and rotate credentials.