kevmap

Log sources › saas:salesforce

saas:salesforce

Inverted view: what can be detected if this is the log you have. SaaS

5
channels
5
analytics
5
techniques
1
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
API login using access_token without login history DC0002 User Account Authentication AN0528 1
ConnectedApp OAuth policy change / Login as user DC0088 Logon Session Metadata AN1349 1
DataExport, RestAPI, Login, ReportExport DC0038 Application Log Content AN1520 1
GET /services/data/vXX.X/groups DC0099 Group Enumeration AN0697 1
Login DC0002 User Account Authentication AN0811 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1069.003 Cloud Groupsdiscovery10
T1199 Trusted Relationshipinitial access21
T1213.004 Customer Relationship Management Softwarecollection00
T1538 Cloud Service Dashboarddiscovery00
T1550.001 Application Access Tokenlateral movement40

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2024-53704SonicWall SonicOS T1199 Mapped