Detecting SaaS Credential Stuffing: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from June 2024, written in 2026 with the benefit of hindsight.
Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.
Signals worth watching
- Sign-ins to SaaS platforms using local passwords instead of SSO.
- Sign-ins from new IP addresses, VPS providers or anonymizing services.
- Accounts dormant for months suddenly active.
- Large query results or data exports.
- New users, roles or API keys created.
- Your employees' credentials appearing in infostealer log feeds (threat intelligence).
Where the data lives
- SaaS audit logs (for Snowflake,
LOGIN_HISTORYandQUERY_HISTORYviews). - Defender for Cloud Apps activity logs for connected apps.
- Entra ID sign-in logs for SSO-integrated access.
- Threat intelligence and credential exposure monitoring services.
A starting approach for Snowflake
Query login history for password-based sign-ins and new client IPs:
SELECT event_timestamp, user_name, client_ip, reported_client_type, first_authentication_factor, second_authentication_factor
FROM snowflake.account_usage.login_history
WHERE first_authentication_factor = 'PASSWORD'
AND second_authentication_factor IS NULL
AND event_timestamp > DATEADD(day, -7, CURRENT_TIMESTAMP());
Then review query history for large SELECT or COPY INTO operations from those sessions.
Response
- Disable the account and rotate credentials.
- Identify data queried and exported.
- Find the infected device that leaked credentials.
- Enforce SSO and MFA platform-wide.