On-Demand Videos & Webinars

Snowflake Attacks: The Runtime Blind Spot

Snowflake is where a lot of companies keep their crown jewels — customer records, financials, PII, even their logs. It's built to run analytics on all of it in one place, which is exactly what makes it one of the highest-value targets in the cloud. And here's the uncomfortable part: when an attacker gets in, the whole thing can play out inside Snowflake, using Snowflake's own features. A stolen credential, a COPY command, and the data walks out looking like a routine export. No endpoint agent runs in there. No network tool catches it. The only record is Snowflake's own logs.

In our latest Mitiga Minutes, Brian Contos and Mitiga's Idan Cohen open up the platform and walk through a real client incident. A single service user authenticates from 355 distinct IP addresses in one day — the kind of "typical" machine activity that gets waved through. From there: 53 reconnaissance queries in five minutes, sensitive data copied to an S3 bucket, and a quick climb to ACCOUNTADMIN. Mitiga ingests Snowflake's control-plane and data-plane logs, keeps them, and stitches the whole chain into one story an analyst can actually follow.

If you took one thing from the 2024 Snowflake campaign, let it be this: plenty of teams read the headlines and did nothing. Turn on the logs, retain them, and get them somewhere that can make sense of them in runtime. Then check whether you'd catch the next one.

Related

Tactical Guide to Threat Hunting in Snowflake Environments
Salesforce Attacks Explained: Why SIEM and EDR Miss Them (Mitiga Minutes)
Inside Cloud Threat Detection with Mitiga (Mitiga Minutes)
AI Insights in Action: Mitiga Helios AIDR (Mitiga Minutes)

Don't miss these stories