LoFP
/
github
github rule
Title
Tags
a self-hosted runner is automatically removed from github if it has not connected to github actions for more than 14 days.
t1078
t1078.004
t1213
t1213.003
t1526
github
sigma
allowed administrative activities.
t1020
t1078
t1078.004
t1537
t1562
t1562.001
github
sigma
allowed self-hosted runners changes in the environment.
t1078
t1078.004
t1213
t1213.003
t1526
github
sigma
an ephemeral self-hosted runner is automatically removed from github if it has not connected to github actions for more than 1 day.
t1078
t1078.004
t1213
t1213.003
t1526
github
sigma
approved administrator/owner activities.
t1556
github
sigma
approved changes by the organization owner. please validate the 'actor' if authorized to make the changes.
t1195
t1195.001
github
sigma
archiving or unarchiving a repository is often legitimate. investigate this action to determine if it was authorized.
github
sigma
authorized self-hosted github actions runner.
t1195
github
elastic
legitimate ci/cd automation that commits and pushes changes (e.g., auto-formatting, changelog updates, version bumps, dependabot auto-merge) will trigger this alert on first use in a repository. review the repository's workflow configurations to determine if bot pushes are expected.
t1059
t1195
github
elastic
legitimate ci/cd automation that requires workflow file modifications may trigger this alert if not properly configured with the necessary permissions. review the workflow configuration and ensure the github_token or pat has the required 'workflows' permission if the modification is intentional.
t1059
t1195
t1546
github
elastic
legitimate publishing of repository pages by authorized users
t1567
t1567.001
github
sigma
organization approved new members
t1136
t1136.003
github
sigma
this detection cloud be noisy depending on the environment. it is recommended to keep a check on the new secrets when created and validate the \"actor\".
t1078
t1078.004
github
sigma
validate the actor if permitted to access the repo.
t1098
t1098.001
t1098.003
t1213
t1213.003
github
sigma
validate the deletion activity is permitted. the \"actor\" field need to be validated.
t1213
t1213.003
github
sigma
validate the multifactor authentication changes.
t1098
t1098.001
t1098.003
t1213
t1213.003
github
sigma