
Summary
The Snowflake Grant to Public Role detection rule is designed to identify when additional privileges are granted to the public role within a Snowflake environment. The primary focus is to monitor any grants that enhance access rights to public roles, as assigning excess permissions can pose a security threat by allowing unintended access to sensitive data. Detailed logging of the grants is utilized to verify actions taken by account administrators, hence, it is imperative to review whether privileges granted to the public role are truly necessary. The rule also references relevant MITRE ATT&CK techniques that encompass privilege escalation through valid account exploitation which is critical in maintaining the integrity of user access in the system.
Categories
- Cloud
- Infrastructure
- Database
Data Sources
- Cloud Service
- Application Log
ATT&CK Techniques
- T1078.001
Created: 2024-11-04