Detect anomalous access and bulk reads from reservation databases
Alert on high-volume queries, rare admin accounts, and unusual time-of-day access to sensitive guest tables.
Data sources: Database audit logs, SIEM, Identity access logsunknown low confidence
Cited sources focus on breach disclosure and regulatory outcomes; definitive public attribution is not provided in the included materials.
No CVE or ATT&CK association is captured in this curated record.
Alert on high-volume queries, rare admin accounts, and unusual time-of-day access to sensitive guest tables.
Data sources: Database audit logs, SIEM, Identity access logsIdentify large outbound transfers, especially to unfamiliar hosts or cloud storage, from database subnets.
Data sources: Proxy logs, NetFlow/flow logs, DLP alertss1s2s3