Bitbucket Audit: Full Data Export Triggered

Alerts when Bitbucket audit logging records a full data export being triggered.

FreeReviewedSigma · High · v5
Product
bitbucket
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2024-02-25
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Bitbucket audit events where a full data export is triggered. Full exports can be used by attackers to rapidly exfiltrate large volumes of repository and pipeline data, so distinguishing export activity from normal operations is important. It relies on Bitbucket audit log fields that record the export action under the data pipeline category.

Related detections4 linkedT1213.003 — drag to rearrange
Bitbucket Audit: Unauthorized Full Data Export Triggered (Data Pipeline)
GitHub Audit Log: Self-Hosted Runner Configuration Changes
GitHub Audit: Outside Collaborator Membership and Permission Changes
GitHub Audit Log: Delete Actions for Codespaces, Environments, Projects, and Repositories
Bitbucket Audit: Full Data Export Triggered
Pivot detection · T1213.003 · 4 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.