Log sources › saas:github
saas:github
Inverted view: what can be detected if this is the log you have. SaaS
6
channels
2
analytics
2
techniques
0
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Artifact generated includes base64/encoded exfil payload or URL |
DC0025 Cloud Storage Access | AN1473 | 1 |
Bulk access to multiple files or large volume of repo requests within short time window |
DC0038 Application Log Content | AN0732 | 1 |
CI/CD secret accessed or exported |
DC0070 Cloud Service Metadata | AN1473 | 1 |
Login from unusual IP, device fingerprint, or location; access token creation from new client |
DC0067 Logon Session Creation | AN0732 | 1 |
Workflow triggered via pull_request_target from forked repo |
DC0069 Cloud Service Modification | AN1473 | 1 |
repo.download, repo.clone, oauth.authorize, repo.getContent |
DC0070 Cloud Service Metadata | AN0732 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1213.003 Code Repositories | collection | 5 | 0 |
| T1677 Poisoned Pipeline Execution | execution | 0 | 0 |