heroui logo

Snowflake Temporary Stage Created

Panther Rules

View Source
Summary
The 'Snowflake Temporary Stage Created' detection rule identifies instances where a temporary stage within a Snowflake environment is created. The rule is tagged with 'Info' severity and does not generate alerts. It monitors log types associated with Snowflake Query History, particularly focusing on successful or failed attempts to create temporary stages. A successful creation is logged when the query results indicate a successful status for commands like 'CREATE TEMP STAGE' or 'CREATE OR REPLACE TEMP STAGE.' The detection rule is also mapped to the MITRE ATT&CK framework, specifically targeting the exfiltration methods of adversaries via cloud applications, as denoted in the technique TA0010:T1041.
Categories
  • Cloud
  • Database
  • Application
Data Sources
  • User Account
  • Application Log
ATT&CK Techniques
  • T1041
Created: 2024-11-04