detect-snowflake-session-policy-bypass
detect-snowflake-session-policy-bypass
Attack pattern
Snowflake session policies (CREATE SESSION POLICY, ALTER SESSION POLICY)
control how long a session can stay idle (SESSION_IDLE_TIMEOUT_MINS) and how
long the web UI session can stay idle (SESSION_UI_IDLE_TIMEOUT_MINS) before
the user is forced to re-authenticate.
A compromised credential or insider trying to extend their useful session
window will raise those thresholds — often to the maximum 240 minutes — so
they don't have to re-enter MFA. On the wire this shows up as an
ALTER_SESSION_POLICY event with a new SESSION_IDLE_TIMEOUT_MINS /
SESSION_UI_IDLE_TIMEOUT_MINS value that exceeds the operator's documented
baseline.
This skill keeps the logic narrow to that pattern. It does not flag every session-policy modification, and it does not guess at every other Snowflake policy.