Whether planned and executed over time or forced overnight by the global pandemic, the worlds digital transformation has prompted a surge in the use of Software-as-a-Service (SaaS) solutions in organizations across the globe. The annual growth rate of the SaaS market iscurrently 18%, and as the global workforce becomes increasingly remote throughout 2020, this figure is only set to skyrocket.
SaaS solutions have been an entry point for cyber-attackers for some time but little attention is given to how the Techniques, Tools & Procedures (TTPs) in SaaS attacks differ significantly from traditional TTPs seen in networks and endpoint attacks.
This raises a number of questions for security experts: how do you create meaningful detections in SaaS environments that dont have endpoint or network data? How can you investigate threats in a SaaS environment? What does a good SaaS environment look like as opposed to one thats threatening? A global shortage in cyber skills already creates problems for finding security analysts able to work in traditional IT environments hiring security experts with SaaS domain knowledge is all the more challenging.
Meanwhile, SaaS consumers are left with limited options: use the native SaaS security controls provided in each SaaS solution and risk a lack of security maturity or go with a third-party SaaS security solution, often in the form of Cloud Access Security Brokers (CASBs). Both options are not without their security risks.
Here are two examples of attacks recently detected by AI in SaaS environments that are representative of the broader SaaS threat landscape, and illuminate the sharp distinction between a traditional network attack and a SaaS compromise.
Office365 Business email compromise
In what amounted to a classic business email compromise (BEC), an attacker infiltrated an employees Microsoft 365 account to access sensitive financial documents hosted in SharePoint, including pay slip and banking details. Having gained initial entry, the attacker proceeded to make configuration changes to the inbox, deleting items and making updates that would enable them to cover their tracks.
The employees account login was first observed from unusual IP ranges. The account in question had never logged in from Bulgaria before, and the peer accounts belonging to those from the same department had not exhibited similar behavioral traits. This in itself was a low-level anomaly and not necessarily indicative of malicious activity after all, in the context of an increasingly distributed workforce, employees might change locations frequently.
Yet the unusual login location was accompanied by an unusual login time and a new User-Agent. All of these anomalies called for a deeper analysis. It was then identified that the account was starting to access highly sensitive information, including payroll information on a Sharepoint.
The attacker tried to gain insights about payment information and credit card details, with the likely intention of changing the payroll details to an attacker-controlled bank account.
AI-powered security technology was able to put together these weak signals of a threat and illuminate the likely account compromise. The companys security team was then able to lock the account and alert the user, who subsequently changed their credentials.
Box.com Compromise
At a global supply company, unauthorized access to an employees Box.com file storage account was detected. The login took place in the US where the company does operate but from an unusual IP space and ASN. AI began to investigate the users activity.
The actor behind the account logged in to Box.com successfully, and proceeded to download expense reports, invoices, and other financial documents. These were files that were highly unusual for the account to access.
Cyber AI also found that the activity occurred at a highly unusual time for the legitimate user, and the location of the actors IP address was anomalous compared to the employees previous access locations for this particular SaaS service.
An understanding of user behavior and granular visibility within the Box.com application allowed the company to spot the subtle signs of account compromise. Moreover, AI-powered investigation outlined the narrative in its entirety, showing how each unauthorized file exposure was part of a connected incident and a key concern for the security team.
A new era in SaaS domain defense
Ultimately, traditional detection approaches with hard and fast rules for how SaaS domains should operate are not enough to ensure that SaaS applications remain secure. Keeping threat intelligence lists up to date is even more difficult, as most SaaS attacks dont involve any Command & Control just indiscriminate logins from remote devices. When it comes to points of entry for SaaS attacks, the possibilities are endless: VPN, Tor, other compromised devices, dynamic DNS or even virtual private servers for attackers to cover their tracks.
A more intricate and effective approach to SaaS security requires an understanding of the dynamic individual behind the account. SaaS applications are fundamentally platforms for humans to communicate allowing them to exchange and store ideas and information.
Abnormal, threatening behavior is therefore impossible to detect without a nuanced understanding of those unique individuals: where and when do they typically access a SaaS account, which files are they like to access, who do they typically connect with? As the attacks outlined serve to demonstrate, these are questions for an AI brain to contend with.
Follow this link:
The Anatomy of a SaaS Attack: Catching and Investigating Threats with AI - Infosecurity Magazine
- Anatomy of the Phillips curve - CEPR - June 10th, 2025 [June 10th, 2025]
- Don't Expect Arizona To Return To Grey's Anatomy Anytime Soon After This Exciting Jessica Capshaw Update - Screen Rant - June 10th, 2025 [June 10th, 2025]
- Pacers vs. Thunder NBA Finals: Anatomy of a comeback How the Pacers once again did the unthinkable - Yahoo Sports - June 10th, 2025 [June 10th, 2025]
- Anatomy Of A Debacle: How Mayor Adams Went From Visionary to Bully on E-Bikes - Streetsblog New York City - June 10th, 2025 [June 10th, 2025]
- Anatomy of an At-Bat: How Matt Wallner Conquered Kevin Gausman - Twins Daily - June 10th, 2025 [June 10th, 2025]
- Enhancing anatomy education with virtual reality: integrating three-dimensional models for improved learning efficiency and student satisfaction -... - June 10th, 2025 [June 10th, 2025]
- Greys Anatomy Season 22 Cast Updates: Just Two Actors Confirmed After Shocking Finale, Though 7 More Stars Have Deals to Return - Just Jared - June 10th, 2025 [June 10th, 2025]
- S11E20: 5 Things You Should Know About Tactical Anatomy With Steve Moses - concealedcarry.com - June 10th, 2025 [June 10th, 2025]
- Airport security held Greys Anatomy star for an hour over snack - Yahoo - June 10th, 2025 [June 10th, 2025]
- Wine Walk: The anatomy of a wine bottle, its cork and how it is sealed - The Courier of Montgomery County - June 10th, 2025 [June 10th, 2025]
- MSc grad reflects on learning and legacy in the anatomy lab - Schulich School of Medicine & Dentistry - June 10th, 2025 [June 10th, 2025]
- Greys Anatomy star Ellen Pompeo says TSA detained her over sunflower seeds - Washington Times - June 10th, 2025 [June 10th, 2025]
- Cardiac Anatomy & Orientation of the 3D Heart Part 3 - University of Nebraska Medical Center - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy Star Chris Carmack Teases Link and Jos Season 22 Storyline: Anything Can Happen - Life & Style - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy Star Reveals Her Secret to Flying Under the Radar on Planes - EntertainmentNow - June 1st, 2025 [June 1st, 2025]
- None of her preserved anatomy looked like any other fossil. Scientists Realize That A Fossil Thats Millions Of Years Old Was Fossilized From The... - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy star is fighting to get Denzel Washington on the show: 'Im hoping he does it' - GeekSided - June 1st, 2025 [June 1st, 2025]
- No, Sandra Oh is not watching Greys Anatomy in her free time - GeekSided - June 1st, 2025 [June 1st, 2025]
- Brigitte and Emmanuel Macron the anatomy of a slap - The Spectator World - June 1st, 2025 [June 1st, 2025]
- Sandra Oh Reveals If She Watches Grey's Anatomy Reruns 11 Years Since Cristina Yang Left The Show - Screen Rant - June 1st, 2025 [June 1st, 2025]
- Fan-Favorite Greys Anatomy Star Sandra Oh Reveals Whether She Still Watches the Show or Not - Collider - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy: Why Did Sandra Oh Leave The Show? Revisiting Her Shocking Exit & Remarkable Legacy - Koimoi - June 1st, 2025 [June 1st, 2025]
- Warfare at night, deepfakes by day: The anatomy of a rumour in modern era conflicts - The Indian Express - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy Hunk, 59, Turns Heads in Rare Monaco Outing With Wife - parade.com - June 1st, 2025 [June 1st, 2025]
- Grey's Anatomy season 22 confirmed to premiere in fall 2025 - GeekSided - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy season 21 finale: Where to watch for free tonight - MassLive - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Showrunner Meg Marinis Confirms Your Fears After That Explosive Cliffhanger Finale - The Hollywood Reporter - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' Recap: Did Firebomb Just Kill Off Lucas Adams, Teddy Altman, or Miranda Bailey? - TV Insider - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy season 22 will not introduce any major new additions: 'I have a big enough cast as it is' - GeekSided - May 21st, 2025 [May 21st, 2025]
- 8 Biggest Unanswered Questions & Mysteries After The Grey's Anatomy Season 21 Finale - Screen Rant - May 21st, 2025 [May 21st, 2025]
- Only 2 Grey's Anatomy characters are confirmed to be safe in season 22 - GeekSided - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy': Meredith Puts Herself in Harm's Way Once Again as a Hostage Situation Leaves Grey Sloan Reeling - People.com - May 21st, 2025 [May 21st, 2025]
- This Greys Anatomy character death still remains the shows most gut-wrenching - GeekSided - May 21st, 2025 [May 21st, 2025]
- Anatomy Of A Perfect Trip Cybercaf Across The Algarve - Quartersnacks - May 21st, 2025 [May 21st, 2025]
- Why the Greys Anatomy Hospital Is Facing Another Bomb Threat in Season 21 Finale - E! Online - May 21st, 2025 [May 21st, 2025]
- Streaming Set Another Record In April, But Greys Anatomy And The White Lotus Prove Linears Reach, Nielsen Says - Deadline - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' Boss Answers the Biggest Questions From That Explosive Season Finale (Exclusive) - parade.com - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Season-Finale Recap: Explosions in the Sky - Vulture - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Boss Breaks Down That Explosive Season 21 Finale Cliffhanger, Merediths Surprising Decision - TheWrap - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy boss confirms one new star will return in season 22 - GeekSided - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Season 21 Finale Review: I Cant Believe The Show Pulled Off This Cliffhanger Reminiscent Of Its Glory Days - Screen Rant - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy Finale Preview: Chris Carmack Teases 'Be Afraid' - Us Weekly - May 21st, 2025 [May 21st, 2025]
- ABC NEWS STUDIOS ANNOUNCES HEY BEAUTIFUL: ANATOMY OF A ROMANCE SCAM BEGINS STREAMING MAY 20, ONLY ON HULU - dgepress.com - May 21st, 2025 [May 21st, 2025]
- 5 Grey's Anatomy characters who might not return for season 22 after that fiery cliffhanger - GeekSided - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Explosion & Possible Character Deaths: Showrunner Explains Why Shes Doing This to Link & Jo - Just Jared - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' season 21 ending explained: Is Meredith returning to Grey Sloan for good? - Entertainment Weekly - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy Season 21 Finally Resolved Its Most Frustrating Plot In Limbo - Screen Rant - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy Season 21 Ending Explained: Amelia Survives A Near-Death Experience While Tragedy Strikes A Fan-Favorite - Screen Rant - May 21st, 2025 [May 21st, 2025]
- James Pickens Jr. Says Every Day Is an Adventure on 'Greys Anatomy' (Exclusive) - People.com - May 21st, 2025 [May 21st, 2025]
- The Doctor Is Out: Greys Anatomy Ends Season 21 With a Devastating Death - Yahoo - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Season 22 Cast: Only 2 Characters Confirmed Alive After Finale, Though 7 More Actors Have Deals to Return - Just Jared - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' Interview: James Pickens Jr. Reflects on Pilot and Reveals Season 22 Hopes (Exclusive) - TV Insider - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy tells fans to "brace yourself" for season finale that's as dramatic as this iconic episode - Digital Spy - May 21st, 2025 [May 21st, 2025]
- I Can't Believe Grey's Anatomy Still Hasn't Told Us Who Adams' Mother Is - Cinemablend - May 21st, 2025 [May 21st, 2025]
- Katherine Heigl Shares Why She's Grateful Her Daughters Aren't Interested in Grey's Anatomy (Exclusive) - parade.com - May 12th, 2025 [May 12th, 2025]
- 'Grey's Anatomy' Fans Are Just Realizing This Fun Fact About the Series That Affects All but 1 Episode - People.com - May 12th, 2025 [May 12th, 2025]
- In a Nutshell: Turning anatomy education into online sensation - Ohio University - May 12th, 2025 [May 12th, 2025]
- 'Grey's Anatomy' Gets Musical Again: Link Serenades Jo With Song at the Wedding Altar - TV Insider - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Boss Unpacks Jo and Links Momentous Wedding Song, Teases Bonkers Season 21 Finale - TheWrap - May 12th, 2025 [May 12th, 2025]
- Generating cervical anatomy labels using a deep ensemble multi-class segmentation model applied to transvaginal ultrasound images - Nature - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy creator Shonda Rhimes reveals the hardest death she had to write - Yahoo - May 12th, 2025 [May 12th, 2025]
- Katherine Heigl Reveals What 1 Medical Trick She Thinks She Could Still Do After Grey's Anatomy (Exclusive) - parade.com - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Season 21, Episode 17 Review: As A Long-Time Fan, I Loved This Romantic & Poignant Episode That Felt Like Classic Greys - Screen... - May 12th, 2025 [May 12th, 2025]
- As One Greys Anatomy Couple Weds, Another Breaks Up and a Third Relationship Lands on Life Support - TVLine - May 12th, 2025 [May 12th, 2025]
- Every Wedding on Greys Anatomy , Ranked - Vulture - May 12th, 2025 [May 12th, 2025]
- 'Greys Anatomy': Link Surprises Jo at Their Wedding, Owen Holds onto the Past and 1 Couple Calls It Quits - People.com - May 12th, 2025 [May 12th, 2025]
- Here comes the bride: Where to stream Greys Anatomy for FREE - PennLive.com - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Preview: Will Link and Jo I Do It Right On Their Wedding Day? Plus, [Spoiler]s Back - TVLine - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy boss reveals the disappointing reason Meredith missed Jo and Links wedding - GeekSided - May 12th, 2025 [May 12th, 2025]
- Anatomy Of Startup Governance Issues, Funding Zooms & More - StartupNews.fyi - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Shock: Lucas and Simone Split Will Fans Even Miss Them? - Decatur Metro - May 12th, 2025 [May 12th, 2025]
- 9 Secrets of the Greys Anatomy Sets Superfans Need to Know - Architectural Digest - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Continues to Ignore a Key Character's Storyline (& It's Frustrating Fans) - Comic Book Resources - May 12th, 2025 [May 12th, 2025]
- Jo & Link's Unique Wedding Set-Up Is Exactly Why Their Romance Works In Grey's Anatomy - Screen Rant - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy creator Shonda Rhimes reveals the hardest death she had to write - The Independent - May 12th, 2025 [May 12th, 2025]
- Grey's Anatomy fans are just realizing clever aspect of 'every episode' after 20 years - The Mirror US - May 12th, 2025 [May 12th, 2025]
- Did the Success of The Substance and Anatomy of a Fall Finally Teach Cannes a Lesson? - IndieWire - May 12th, 2025 [May 12th, 2025]
- Grey's Anatomy fans floored after spotting 'hidden message' in every episode - Irish Star - May 12th, 2025 [May 12th, 2025]
- Anatomy of an apprehension: Where are you taking the baby? - Maple Ridge-Pitt Meadows News - May 12th, 2025 [May 12th, 2025]
- Isaiah Washington Says Sandra Oh Brought Him Back on Greys Anatomy Years After Firing - E! Online - April 27th, 2025 [April 27th, 2025]