SnowSentry Trust Center Extension
收藏Snowflake2026-03-23 更新2026-03-27 收录
下载链接:
https://app.snowflake.com/marketplace/listing/GZSTZ67BY9QWW
下载链接
链接失效反馈官方服务:
资源简介:
# Sentry Trust Center Extension
A [Trust Center extension](https://docs.snowflake.com/en/user-guide/trust-center/trust-center-extensions#develop-a-trust-center-extension) based on [Snowflake Sentry](https://github.com/Snowflake-Labs/Sentry) security scanners. Install the application to integrate scanner packages with the Trust Center and continuously monitor your Snowflake account for vulnerabilities, misconfigurations, and suspicious activity.
This extension provides additional security coverage beyond the native first-party scanner packages on Trust Center (e.g., CIS Benchmarks, Threat Intelligence). Furthermore, it is designed to serve as a comprehensive template, providing your team with a foundation to build, customize, and deploy your own custom scanning logic on top of the Trust Center.
***Please note:** While the application is free to install, executing the scanners utilizes Snowflake compute resources and will incur credit consumption.*
<p><br/></p>
# Scanner packages
After installation, the following **6 scanner packages** are expected to be available in the Trust Center.
<p><br/></p>
## Secrets & Privileged Access
Scans for security risks related to credential management, privileged access grants, and sensitive configuration changes that could expose the account to unauthorized access.
- **Stale users** (Violation/Vulnerability) — Detects inactive user accounts
- **Grants to PUBLIC role** (Detection) — Detects privileges granted to all users
- **Privileged object changes** (Detection) — Monitors changes to sensitive objects
- **Grants to unmanaged schemas** (Violation/Vulnerability) — Detects grants bypassing schema ownership
- **Default role is ACCOUNTADMIN** (Violation/Vulnerability) — Users defaulting to full admin privileges
<p><br/></p>
## Roles
Scans for security risks in role-based access control including overly permissive roles, dangerous role grants, and unused access that violates least-privilege principles.
- **ACCOUNTADMIN grants** (Detection) — Detects grants of full admin access
- **Bloated Roles** (Violation/Vulnerability) — Roles with excessive privileges
- **Least Used Role Grants** (Violation/Vulnerability) — Identifies dormant role assignments
<p><br/></p>
## Users
Scans for security risks related to user accounts including excessive access concentration, stale credentials, and accounts that may pose elevated risk if compromised.
- **Most dangerous user** (Violation/Vulnerability) — Users with concentrated access
- **Users by Password Age** (Violation/Vulnerability) — Detects stale passwords
<p><br/></p>
## Configuration
Scans for changes to security-critical configurations that control network access, authentication policies, and account-level settings.
- **Network policy changes** (Detection) — Monitors network access control changes
<p><br/></p>
## Authentication
Scans for authentication-related security events including failed login attempts that may indicate credential attacks or account compromise attempts.
- **Number of login failures** (Detection) — Detects potential credential attacks
<p><br/></p>
## Sharing
Scans for changes to data sharing configurations including shares, listings, and reader accounts that could expose data to unintended external parties.
- **Reader account creation** (Detection) — Detects new external access points
- **Listing changes monitor** (Detection) — Monitors Marketplace listing changes
- **SHAREs changes monitor** (Detection) — Monitors data share modifications
提供机构:
Snowflake
创建时间:
2026-03-10
原始信息汇总
SnowSentry Trust Center Extension 数据集概述
数据集名称
SnowSentry Trust Center Extension
提供商
Snowflake
访问权限与费用
- 费用:免费安装
- 访问权限:无限访问
- 重要说明:执行扫描器会消耗 Snowflake 计算资源并产生计算积分费用。
数据集描述
这是一个基于 Snowflake Sentry 安全扫描器的 Trust Center 扩展。安装该应用程序可将扫描器包与 Trust Center 集成,持续监控 Snowflake 账户中的漏洞、错误配置和可疑活动。该扩展提供了超出 Trust Center 原生第一方扫描器包(例如 CIS 基准、威胁情报)的额外安全覆盖范围。此外,它被设计为一个全面的模板,为您的团队提供基础,以便在 Trust Center 之上构建、定制和部署您自己的自定义扫描逻辑。
主要功能与覆盖范围
扫描器包
安装后,预计 Trust Center 中将提供以下 6 个扫描器包:
-
Secrets & Privileged Access
- 扫描与凭证管理、特权访问授予以及可能使账户面临未授权访问风险的敏感配置更改相关的安全风险。
- 包含检测项:
- Stale users (违规/漏洞) — 检测非活动用户账户
- Grants to PUBLIC role (检测) — 检测授予所有用户的权限
- Privileged object changes (检测) — 监控敏感对象的更改
- Grants to unmanaged schemas (违规/漏洞) — 检测绕过模式所有权的授权
- Default role is ACCOUNTADMIN (违规/漏洞) — 默认拥有完全管理员权限的用户
-
Roles
- 扫描基于角色的访问控制中的安全风险,包括过度宽松的角色、危险的角色授予以及违反最小权限原则的未使用访问权限。
- 包含检测项:
- ACCOUNTADMIN grants (检测) — 检测完全管理员访问权限的授予
- Bloated Roles (违规/漏洞) — 拥有过多权限的角色
- Least Used Role Grants (违规/漏洞) — 识别闲置的角色分配
-
Users
- 扫描与用户账户相关的安全风险,包括访问权限过度集中、过时的凭证以及如果被入侵可能构成更高风险的账户。
- 包含检测项:
- Most dangerous user (违规/漏洞) — 访问权限集中的用户
- Users by Password Age (违规/漏洞) — 检测过时的密码
-
Configuration
- 扫描控制网络访问、身份验证策略和账户级别设置的安全关键配置的更改。
- 包含检测项:
- Network policy changes (检测) — 监控网络访问控制更改
-
Authentication
- 扫描与身份验证相关的安全事件,包括可能表明凭证攻击或账户入侵尝试的失败登录尝试。
- 包含检测项:
- Number of login failures (检测) — 检测潜在的凭证攻击
-
Sharing
- 扫描数据共享配置的更改,包括可能将数据暴露给意外外部方的共享、列表和读取器账户。
- 包含检测项:
- Reader account creation (检测) — 检测新的外部访问点
- Listing changes monitor (检测) — 监控 Marketplace 列表更改
- SHAREs changes monitor (检测) — 监控数据共享修改
业务需求
风险分析
SnowSentry Trust Center Extension 扫描您的 Snowflake 账户中用户访问、角色配置、身份验证、网络策略和数据共享方面的漏洞。通过可操作的发现来检测错误配置和可疑活动,从而加强您的安全态势。
安全信息
- 安全框架:原生应用程序框架,设计安全
- 安全审查:此应用程序经过了 Snowflake 安全审查。
- 访问控制:您的数据受 Snowflake 基于角色的访问控制保护。
- 安装后建议:提供商建议根据需要授予以下权限:
- 账户级别权限
- 对象权限
- 连接
- 应用程序事件
类别
- 风险分析
- Trust Center 扩展
时间覆盖范围
- 最近 7 天
- 按天
地理覆盖范围
- 全球
- 按州
云区域可用性
AWS
- Africa (Cape Town)
- Asia Pacific (Jakarta)
- Asia Pacific (Mumbai)
- Asia Pacific (Osaka)
- 49 More
法律条款
标准
联系信息
- 销售:snowflake-provider@snowflake.com
- 支持:https://snowflake.com/support



