Suspicious Salesforce Bulk Data Extraction via Bulk and Report APIs

PremiumReviewedSigma · Medium · v1
Product
saas
Service
salesforce
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Collection → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Impact

What it detects

This rule detects Salesforce bulk-processing and report-export events combined with paginated query bursts, matching UNC6040 mass extraction driven through a malicious connected app based on a modified Data Loader. Attackers use these high-volume APIs to enumerate and exfiltrate large volumes of records after voice-phishing a user into authorizing the app.

Related detections9 linkedT1567 — drag to rearrange
Possible Discord Webhook C2 or Data Exfiltration
Suspicious Environment Variable Dump Piped to Base64 for CI Credential Exfil
Suspicious Salesforce Bulk Query by External App with Python-urllib Agent
Malicious Destructive Recursive Delete of Home Directory
Malicious Madgicx Plus Extension C2 Domain Resolution
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Suspicious HTTP POST to Local AI Malware Exfil Endpoint (via proxy)
Malicious Mini Shai-Hulud TanStack C2 git-tanstack and getsession (via dns_query)
Suspicious Data Exfiltration to Webhook.site via Command Line (via process_creation)
Suspicious Salesforce Bulk Data Extraction via Bulk and Report APIs
Pivot detection · T1567 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.