Bitbucket audit: Project secret scanning allowlist rule added
Alerts when Bitbucket records a project secret scanning allowlist rule being added via the audit log.
- Product
- bitbucket
- Service
- audit
- Author
- Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
- Published
- 2024-02-25
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Bitbucket audit events where a secret scanning allowlist rule is added for a project. Attackers can use allowlists to bypass or reduce the effectiveness of secret detection, making the change an indicator of defense impairment. It relies on Bitbucket audit telemetry capturing the audit type category as Projects and the specific action for adding the allowlist rule.
Reporting behind it
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_project_secret_scanning_allowlist_added.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Bitbucket audit: Project secret scanning allowlist rule added"
id: 365be920-8c7f-49fc-9266-d67d49e41db8
status: test
description: This rule flags Bitbucket audit events where a secret scanning allowlist rule is added for a project. Attackers can use allowlists to bypass or reduce the effectiveness of secret detection, making the change an indicator of defense impairment. It relies on Bitbucket audit telemetry capturing the audit type category as Projects and the specific action for adding the allowlist rule.
references:
- https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_project_secret_scanning_allowlist_added.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: bitbucket
service: audit
definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
selection:
auditType.category: Projects
auditType.action: Project secret scanning allowlist rule added
condition: selection
falsepositives:
- Legitimate user activity.
level: low
license: DRL-1.1
related:
- id: 42ccce6d-7bd3-4930-95cd-e4d83fa94a30
type: derived