Bitbucket Audit: Unauthorized Full Data Export Triggered (Data Pipeline)

Flags Bitbucket audit events indicating an unauthorized user attempted a full data export.

FreeReviewedSigma · Critical · v5
Product
bitbucket
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2024-02-25
Updated
2026-07-31

ATT&CK techniques

Resource Dev → Collection
  1. Recon

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Bitbucket audit events where an "Unauthorized full data export triggered" action occurs under the "Data pipeline" category. Attempting full exports can indicate data theft or reconnaissance beyond normal user permissions. It relies on Bitbucket audit telemetry that records the audit type category and action for export attempts.

Related detections5 linkedT1213.003 — drag to rearrange
Bitbucket Audit: Full Data Export Triggered
Bitbucket Audit: Unauthorized Access to a Resource
GitHub Audit Log: Self-Hosted Runner Configuration Changes
GitHub Audit: Outside Collaborator Membership and Permission Changes
GitHub Audit Log: Delete Actions for Codespaces, Environments, Projects, and Repositories
Bitbucket Audit: Unauthorized Full Data Export Triggered (Data Pipeline)
Pivot detection · T1213.003 · 5 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.