Bitbucket Global Secret Scanning Rule Deleted (Audit Logs)

Alerts on Bitbucket audit events indicating a global secret scanning rule was deleted.

FreeReviewedSigma · Medium · v5
Product
bitbucket
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2024-02-25
Updated
2026-07-31
title: Bitbucket Global Secret Scanning Rule Deleted (Audit Logs)
id: c490fda1-685d-4211-9941-6b942f599966
status: test
description: This rule identifies when a Bitbucket global secret scanning rule is deleted via an audit event. Attackers may remove secret scanning controls to reduce the chance of detecting sensitive data exposure or configuration issues. The detection relies on Bitbucket audit log telemetry capturing the event category and action for global administration and rule deletion.
references:
  - https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
  - https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_global_secret_scanning_rule_deleted.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  product: bitbucket
  service: audit
  definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
  selection:
    auditType.category: Global administration
    auditType.action: Global secret scanning rule deleted
  condition: selection
falsepositives:
  - Legitimate user activity.
level: medium
license: DRL-1.1
related:
  - id: e16cf0f0-ee88-4901-bd0b-4c8d13d9ee05
    type: derived