Suspicious Salesforce Bulk Query by External App with Python-urllib Agent

PremiumReviewedSigma · Medium · v1
Product
salesforce
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects an external Salesforce application issuing bulk record queries using a Python-urllib user agent, the data theft pattern of the Klue supply chain attack. The actor drove QueryMore bulk reads against the query API from an external application client using a scripted urllib agent rather than a browser. Bulk querying of Salesforce objects by an external app with a scripting user agent indicates automated data exfiltration.

Related detections9 linkedT1078 — drag to rearrange
Suspicious Snowflake Anomalous Client Application Associated With UNC5537 (via cloud)
Suspicious Salesforce OAuth Refresh Token Use by Klue Battlecards App
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
Suspicious SQL Server - Connection Attempt Using a Disabled Account (via application)
Suspicious Lateral Movement Detection - Based on "special Groups" Feature (via security)
Malicious Network Login Performed to Multiple Targets (via security)
Malicious RDP Reconnaissance with Valid Credentials Performed on Multiple Hosts (via security)
Suspicious Salesforce Bulk Query by External App with Python-urllib Agent
Pivot detection · T1078 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.