Bitbucket Audit: Secret Scanning Exempt Repository Added

Flags Bitbucket audit events where a repository is added as exempt from secret scanning.

FreeReviewedSigma · High · v5
Product
bitbucket
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2024-02-25
Updated
2026-07-31
title: "Bitbucket Audit: Secret Scanning Exempt Repository Added"
id: ac478d76-81a6-4a89-8b9d-92d940c4e80d
status: test
description: This rule flags Bitbucket audit events where a repository is added to the secret scanning exempt list. Attackers may use exemptions to avoid automated detection of exposed credentials in repositories. The detection relies on Bitbucket audit log telemetry identifying the repository category and the specific action "Secret scanning exempt repository added".
references:
  - https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
  - https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_exempt_repository_detected.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  product: bitbucket
  service: audit
  definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
  selection:
    auditType.category: Repositories
    auditType.action: Secret scanning exempt repository added
  condition: selection
falsepositives:
  - Legitimate user activity.
level: high
license: DRL-1.1
related:
  - id: b91e8d5e-0033-44fe-973f-b730316f23a1
    type: derived