Bitbucket Audit: Global SSH Settings Changed

Alerts on Bitbucket global SSH settings changes from audit logs under the Global administration category.

FreeReviewedSigma · Medium · v5
Product
bitbucket
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2024-02-25
Updated
2026-07-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies changes to Bitbucket global SSH access configuration by matching audit events labeled with category "Global administration" and action "SSH settings changed." Attackers may abuse global SSH settings to enable access paths or weaken authentication boundaries, making unauthorized configuration changes important to review. It relies on Bitbucket audit log telemetry containing the relevant audit category and action fields for these administrative updates.

Related detections9 linkedT1021.004 — drag to rearrange
Malicious Bad Apples Remote Apple Events Lateral Movement via osascript
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
OpenSSH Server Listening on Socket (via openssh)
Suspicious macOS SSH Loopback Connection for TCC Bypass
Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Bitbucket Audit: Global SSH Settings Changed
Pivot detection · T1021.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.