detect-snowflake-unauthorized-grant
Installation
SKILL.md
detect-snowflake-unauthorized-grant
Attack pattern
Snowflake's role hierarchy puts a small set of system roles
(ACCOUNTADMIN, SECURITYADMIN, ORGADMIN) at the top of every account.
Any user holding one of these roles can read every table, alter every
warehouse, and grant the role onward. An attacker who reaches a role with
OWNERSHIP on ACCOUNTADMIN (or MANAGE GRANTS) can grant a privileged
role to an attacker-controlled identity outside the documented break-glass
process, persisting access until a human notices.
On the wire the pattern is:
GRANT ROLE ACCOUNTADMIN TO USER <name>GRANT ROLE SECURITYADMIN TO USER <name>GRANT ROLE ORGADMIN TO USER <name>