datadog-security-labs · Crawled Jul 18, 2026
Mapping out your unknown: A threat hunter’s guide to Salesforce
Read original article ↗AI Summary
Threat actors are targeting Salesforce environments by exploiting compromised credentials, OAuth tokens, and misconfigured guest accounts to gain unauthorized access. They perform reconnaissance by querying API endpoints to enumerate resources, discover data objects, and assess API usage limits. This activity is often followed by data enumeration and potential exfiltration, leveraging legitimate authentication mechanisms to blend in with normal traffic. Attackers may use brute-force techniques against weak MFA methods or socially engineer users to approve malicious connected apps.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.