Multi-CloudDetection & ResponseRetrospectives

Detecting SaaS Credential Stuffing: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2024, written in 2026 with the benefit of hindsight.

Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.

Signals worth watching

  • Sign-ins to SaaS platforms using local passwords instead of SSO.
  • Sign-ins from new IP addresses, VPS providers or anonymizing services.
  • Accounts dormant for months suddenly active.
  • Large query results or data exports.
  • New users, roles or API keys created.
  • Your employees' credentials appearing in infostealer log feeds (threat intelligence).

Where the data lives

  • SaaS audit logs (for Snowflake, LOGIN_HISTORY and QUERY_HISTORY views).
  • Defender for Cloud Apps activity logs for connected apps.
  • Entra ID sign-in logs for SSO-integrated access.
  • Threat intelligence and credential exposure monitoring services.

A starting approach for Snowflake

Query login history for password-based sign-ins and new client IPs:

SELECT event_timestamp, user_name, client_ip, reported_client_type, first_authentication_factor, second_authentication_factor
FROM snowflake.account_usage.login_history
WHERE first_authentication_factor = 'PASSWORD'
  AND second_authentication_factor IS NULL
  AND event_timestamp > DATEADD(day, -7, CURRENT_TIMESTAMP());

Then review query history for large SELECT or COPY INTO operations from those sessions.

Response

  1. Disable the account and rotate credentials.
  2. Identify data queried and exported.
  3. Find the infected device that leaked credentials.
  4. Enforce SSO and MFA platform-wide.
detect saas credential stuffingSnowflake customer breaches2024

More on this story