Salesforce Detection Pack
36 detection rules for Salesforce Event Monitoring and Setup Audit Trail — covering bulk CRM data export, admin privilege abuse, Connected App OAuth threats, and account takeover. Your CRM holds your most valuable customer data.
Pack summary
- Detection rules
- 36
- Critical severity
- 9
- Log sources
- 4
- ATT&CK techniques
- 11
What's included
36 rules across 5 threat categories for Salesforce security threats.
Report exports, Bulk API jobs, Data Export service, analytics dataset sharing, SOQL exfil.
Login from new IP, SSO bypass, failed login spikes, session hijacking indicators.
System Admin profile grants, Login-As impersonation, IP restriction removal, MFA disabling.
Connected App creation, Remote Site Settings, Named Credential changes, Apex deployment.
Field history tracking disabling, debug log enables on admin accounts.
Detection rules (20 of 36 shown)
Showing 20 representative rules. All 36 rules activate with one click.
| Rule name | Severity |
|---|---|
| Salesforce Report Exported — High Row Count | High |
| Salesforce Bulk API — Mass Record Export | Critical |
| Salesforce System Administrator Profile Assigned | Critical |
| Salesforce Login from New IP — No Prior History | High |
| Salesforce Connected App Created with Broad OAuth Scope | High |
| Salesforce Session Hijacking — Login Without Single Sign-On | High |
| Salesforce Data Export Service Initiated | Critical |
| Salesforce Remote Site Setting Added to Unknown Domain | High |
| Salesforce Debug Log Enabled for Admin User | Medium |
| Salesforce User Login as Another User (Login-As) | High |
| Salesforce IP Restrictions Removed | Critical |
| Salesforce Apex Code Deployed to Production | High |
| Salesforce Field History Tracking Disabled | Medium |
| Salesforce SOQL Query Against Sensitive Object — External Callout | High |
| Salesforce Guest User Profile — CRUD Permissions Added | High |
| Salesforce MFA Requirement Disabled | Critical |
| Salesforce Workflow Rule Created to External Email | High |
| Salesforce Login Failure Spike | High |
| Salesforce Named Credential Modified — External Endpoint | High |
| Salesforce Einstein Analytics Dataset Shared Externally | High |
Prerequisites
- Salesforce Event Monitoring add-on (included in Salesforce Shield or available as a standalone add-on for Enterprise and above)
- Connected App configured with OAuth 2.0 and full or api scope for REST API access
- Setup Audit Trail access via the SetupAuditTrail object (available in all editions)
- Salesforce Shield Event Monitoring recommended for real-time streaming (otherwise polling interval is 1 hour for EventLogFile)
Salesforce Detection Pack: frequently asked questions
What Salesforce log sources does this detection pack use?
The Salesforce detection pack uses Salesforce Event Monitoring (real-time or log file downloads via the EventLogFile object), Setup Audit Trail (configuration changes), Login History, and the Salesforce Shield Event Monitoring API for real-time streaming. ManySignal connects via the Salesforce REST API using a connected app with appropriate OAuth scopes.
Does this pack require Salesforce Shield?
Salesforce Shield Event Monitoring provides real-time streaming and enhanced log fidelity. The detection pack can operate without Shield using periodic EventLogFile polling (daily or hourly log files), but real-time detection requires Shield Event Monitoring. Shield also unlocks Field Audit Trail and Platform Encryption monitoring.
How does ManySignal detect Salesforce data exfiltration?
Salesforce exfiltration detection focuses on report exports above historical baseline, Bulk API jobs extracting large object volumes, and the native Data Export service initiation. ManySignal correlates export events with the user's authentication history — an export immediately following a login from a new IP or device is flagged as high-confidence exfiltration.
Can ManySignal detect Salesforce insider threat patterns?
Yes. Insider threat patterns include: Login-As impersonation of other users, report exports by users with resignation notices in the HR system (when integrated), Bulk API usage by a user who has never used it before, and Connected App creation with broad OAuth scopes outside of normal development workflows.
How does the Salesforce detection pack handle multi-org environments?
ManySignal supports multiple Salesforce orgs from a single tenant. Each org is configured as a separate connector with its own connected app credentials. Alerts include the org name and instance URL for clear attribution. Cross-org correlation (same user accessing multiple orgs) is supported when user identity is shared via SSO.
Detect CRM data exfiltration before customer data leaves Salesforce
36 Salesforce detection rules covering bulk data export, admin privilege abuse, and account takeover across Event Monitoring and Setup Audit Trail.