Suspicious Salesforce Connected App OAuth Authorization from VPN Egress

PremiumReviewedSigma · Medium · v1
Product
saas
Service
salesforce
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects a Salesforce OAuth authorization for a connected app based on the Data Loader followed by API access from anonymizing VPN egress, matching UNC6040 abuse of a stolen app token to pivot across SaaS platforms. Granting this token lets the actor read and export data and pivot into Okta and Entra from the same infrastructure.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious OAuth Device Code Sign-In to Authentication Broker via Tycoon 2FA
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Suspicious M365 Device Code Authentication Flow via m365
Suspicious Entra ID Password Spraying via ROPC Grant to Azure CLI App
Possible Illicit Consent Grant to OAuth Application via Azure AD
Suspicious Entra ROPC Password Spray Against Azure CLI Client
Suspicious Device Code Authentication via Microsoft Authentication Broker
Malicious Consent to Known Traitorware Mail Clients via Azure AD
Suspicious Salesforce Connected App OAuth Authorization from VPN Egress
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.