Bitbucket Audit: Secret Scanning Exempt Repository Added
Flags Bitbucket audit events where a repository is added as exempt from secret scanning.
FreeReviewedSigma · High · v5
- Product
- bitbucket
- Service
- audit
- Author
- Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
- Published
- 2024-02-25
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Bitbucket audit events where a repository is added to the secret scanning exempt list. Attackers may use exemptions to avoid automated detection of exposed credentials in repositories. The detection relies on Bitbucket audit log telemetry identifying the repository category and the specific action "Secret scanning exempt repository added".
Reporting behind it
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_exempt_repository_detected.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
bitbucket-audit-secret-scanning-exempt-repository-added-b91e8d5e
title: "Bitbucket Audit: Secret Scanning Exempt Repository Added"
id: ac478d76-81a6-4a89-8b9d-92d940c4e80d
status: test
description: This rule flags Bitbucket audit events where a repository is added to the secret scanning exempt list. Attackers may use exemptions to avoid automated detection of exposed credentials in repositories. The detection relies on Bitbucket audit log telemetry identifying the repository category and the specific action "Secret scanning exempt repository added".
references:
- https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_exempt_repository_detected.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: bitbucket
service: audit
definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
selection:
auditType.category: Repositories
auditType.action: Secret scanning exempt repository added
condition: selection
falsepositives:
- Legitimate user activity.
level: high
license: DRL-1.1
related:
- id: b91e8d5e-0033-44fe-973f-b730316f23a1
type: derived