Bitbucket Global Secret Scanning Rule Deleted (Audit Logs)
Alerts on Bitbucket audit events indicating a global secret scanning rule was deleted.
FreeReviewedSigma · Medium · v5
- Product
- bitbucket
- Service
- audit
- Author
- Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
- Published
- 2024-02-25
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies when a Bitbucket global secret scanning rule is deleted via an audit event. Attackers may remove secret scanning controls to reduce the chance of detecting sensitive data exposure or configuration issues. The detection relies on Bitbucket audit log telemetry capturing the event category and action for global administration and rule deletion.
Reporting behind it
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_global_secret_scanning_rule_deleted.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
bitbucket-audit-global-secret-scanning-rule-deleted-e16cf0f0
title: Bitbucket Global Secret Scanning Rule Deleted (Audit Logs)
id: c490fda1-685d-4211-9941-6b942f599966
status: test
description: This rule identifies when a Bitbucket global secret scanning rule is deleted via an audit event. Attackers may remove secret scanning controls to reduce the chance of detecting sensitive data exposure or configuration issues. The detection relies on Bitbucket audit log telemetry capturing the event category and action for global administration and rule deletion.
references:
- https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_global_secret_scanning_rule_deleted.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: bitbucket
service: audit
definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
selection:
auditType.category: Global administration
auditType.action: Global secret scanning rule deleted
condition: selection
falsepositives:
- Legitimate user activity.
level: medium
license: DRL-1.1
related:
- id: e16cf0f0-ee88-4901-bd0b-4c8d13d9ee05
type: derived