Bitbucket Audit: SSH User Login Failures

Alerts on Bitbucket audit records showing SSH-based user login failures in authentication events.

FreeReviewedSigma · Medium · v5
Product
bitbucket
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2024-02-25
Updated
2026-07-31

ATT&CK techniques

Cred Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

Identifies Bitbucket audit events where an SSH user login attempt fails. Failed authentication is a common precursor to credential guessing or unauthorized access attempts against SSH-enabled Git repositories. The rule relies on Bitbucket audit telemetry that records authentication failures with the SSH-specific action values.

Related detections9 linkedT1021.004 — drag to rearrange
Malicious Bad Apples Remote Apple Events Lateral Movement via osascript
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
Malicious SQL Server - Brutforce Enumeration with Non Existing Users - Login (via application)
Malicious Brutforce Enumeration with Non Existing Users - Login (via security)
OpenSSH Native Server Feature Installation (via powershell)
Malicious Brutforce Enumeration on Windows OpenSSH Server with Non Existing User (via security)
OpenSSH Server Listening on Socket (via openssh)
Suspicious macOS SSH Loopback Connection for TCC Bypass
Bitbucket Audit: SSH User Login Failures
Pivot detection · T1021.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.