Bitbucket Audit: Secret Scanning Exempt Repository Added
Flags Bitbucket audit events where a repository is added as exempt from secret scanning.
FreeUnreviewedSigmahighv1
bitbucket-audit-secret-scanning-exempt-repository-added-b91e8d5e
title: "Bitbucket Audit: Secret Scanning Exempt Repository Added"
id: ac478d76-81a6-4a89-8b9d-92d940c4e80d
status: test
description: This rule detects when Bitbucket records an audit event indicating a repository was added to the secret scanning exempt list. Attackers may use exemptions to reduce visibility into exposed credentials or sensitive data by bypassing secret scanning coverage. The detection relies on Bitbucket audit log events with the repository category and the specific action for secret scanning exemption being added.
references:
- https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_exempt_repository_detected.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: bitbucket
service: audit
definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
selection:
auditType.category: Repositories
auditType.action: Secret scanning exempt repository added
condition: selection
falsepositives:
- Legitimate user activity.
level: high
license: DRL-1.1
related:
- id: b91e8d5e-0033-44fe-973f-b730316f23a1
type: derived
What it detects
This rule detects when Bitbucket records an audit event indicating a repository was added to the secret scanning exempt list. Attackers may use exemptions to reduce visibility into exposed credentials or sensitive data by bypassing secret scanning coverage. The detection relies on Bitbucket audit log events with the repository category and the specific action for secret scanning exemption being added.
Known false positives
- Legitimate user activity.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.