1200KM / detection
T1213.004 Customer Relationship Management Software — Detection Rules
Detection workspace for T1213.004 Customer Relationship Management Software: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0550 Detecting Suspicious Access to CRM Data in SaaS Environments
AN1520 Analytic 1520
Anomalous high-volume access to customer records in CRM software by a non-CRM admin user account, especially following initial authentication from a rare location or device. Behavior includes abnormal access to PII fields or data exports within a short time window.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1213.004 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.