panther-labs / panther-analysis

Built-in Panther detection rules and policies
https://panther.com/
Apache License 2.0
339 stars 173 forks source link

Add saved queries for ongoing Snowflake threats #1248

Closed egibs closed 5 months ago

egibs commented 5 months ago

Background

Snowflake has released additional information on investigating and identifying malicious behavior to Snowflake accounts: https://community.snowflake.com/s/article/Communication-ID-0108977-Additional-Information

This PR adds saved queries to identify malicious behavior.

These queries require that Panther's read-only role has access to the snowflake.account_usage audit database (this may need to be done by the Snowflake admins).

Changes

Testing