Bitbucket Audit: Global Secret Scanning Rule Deleted
Alerts on Bitbucket audit events indicating a global secret scanning rule was deleted.
FreeUnreviewedSigmamediumv1
bitbucket-audit-global-secret-scanning-rule-deleted-e16cf0f0
title: "Bitbucket Audit: Global Secret Scanning Rule Deleted"
id: c490fda1-685d-4211-9941-6b942f599966
status: test
description: This rule flags audit events where Bitbucket records a deletion of a global secret scanning rule. Attackers may remove or disable secret-scanning controls to reduce the chance that sensitive data exposures are detected. The detection relies on Bitbucket audit log fields indicating the audit category and the specific action name for the deletion event.
references:
- https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_global_secret_scanning_rule_deleted.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: bitbucket
service: audit
definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
selection:
auditType.category: Global administration
auditType.action: Global secret scanning rule deleted
condition: selection
falsepositives:
- Legitimate user activity.
level: medium
license: DRL-1.1
related:
- id: e16cf0f0-ee88-4901-bd0b-4c8d13d9ee05
type: derived
What it detects
This rule flags audit events where Bitbucket records a deletion of a global secret scanning rule. Attackers may remove or disable secret-scanning controls to reduce the chance that sensitive data exposures are detected. The detection relies on Bitbucket audit log fields indicating the audit category and the specific action name for the deletion event.
Known false positives
- Legitimate user activity.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.