heroui logo

Snowflake Login Without MFA

Panther Rules

View Source
Summary
The 'Snowflake Login Without MFA' rule is designed to detect and flag login attempts to Snowflake account without multifactor authentication (MFA). The rule is currently disabled and is based on logs from the Snowflake.LoginHistory. The rule scrutinizes login events where the first authentication factor is a password and no secondary authentication factor is used, indicating an absence of MFA. The rule has a medium severity rating and is related to MITRE ATT&CK tactics on Defense Evasion and modifying the authentication process. Two test scenarios are provided: one is a successful login with MFA that should not trigger the alert, and the other is a successful login attempt without MFA which is expected to trigger the alert. As part of the security strategy, enabling this rule would enhance monitoring efforts and potentially reduce unauthorized access risks to Snowflake environments.
Categories
  • Cloud
  • Application
Data Sources
  • User Account
  • Application Log
ATT&CK Techniques
  • T1556
Created: 2024-11-04