Bitbucket Audit: Secret Scanning Rule Deleted for Project or Repository
Flags Bitbucket audit events indicating secret scanning rules were deleted at the project or repository level.
- Product
- bitbucket
- Service
- audit
- Author
- Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
- Published
- 2024-02-25
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Bitbucket audit events where a secret scanning rule is deleted at the project or repository scope. Attackers may remove or disable scanning to reduce visibility into exposed credentials and other secrets. It relies on Bitbucket audit telemetry indicating the affected scope (Projects/Repositories) and the specific deletion actions for secret scanning rules.
Reporting behind it
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- confluence.atlassian.comhttps://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_rule_deleted.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Bitbucket Audit: Secret Scanning Rule Deleted for Project or Repository"
id: 237dbce9-4966-4d69-ab99-a0357f5afbbd
status: test
description: This rule flags Bitbucket audit events where a secret scanning rule is deleted at the project or repository scope. Attackers may remove or disable scanning to reduce visibility into exposed credentials and other secrets. It relies on Bitbucket audit telemetry indicating the affected scope (Projects/Repositories) and the specific deletion actions for secret scanning rules.
references:
- https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
- https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_rule_deleted.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-02-25
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: bitbucket
service: audit
definition: 'Requirements: "Basic" log level is required to receive these audit events.'
detection:
selection:
auditType.category:
- Projects
- Repositories
auditType.action:
- Project secret scanning rule deleted
- Repository secret scanning rule deleted
condition: selection
falsepositives:
- Legitimate user activity.
level: low
license: DRL-1.1
related:
- id: ff91e3f0-ad15-459f-9a85-1556390c138d
type: derived