kevmap

Log sources › saas:github

saas:github

Inverted view: what can be detected if this is the log you have. SaaS

6
channels
2
analytics
2
techniques
0
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Artifact generated includes base64/encoded exfil payload or URL DC0025 Cloud Storage Access AN1473 1
Bulk access to multiple files or large volume of repo requests within short time window DC0038 Application Log Content AN0732 1
CI/CD secret accessed or exported DC0070 Cloud Service Metadata AN1473 1
Login from unusual IP, device fingerprint, or location; access token creation from new client DC0067 Logon Session Creation AN0732 1
Workflow triggered via pull_request_target from forked repo DC0069 Cloud Service Modification AN1473 1
repo.download, repo.clone, oauth.authorize, repo.getContent DC0070 Cloud Service Metadata AN0732 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1213.003 Code Repositoriescollection50
T1677 Poisoned Pipeline Executionexecution00