GitHub Audit: Dependabot Alerts and Security Updates Disabled

Flags GitHub audit events where Dependabot alerts or security updates are disabled for an organization or repositories.

FreeReviewedSigma · High · v5
Product
github
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2023-01-27
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags GitHub audit log events where Dependabot alerts or Dependabot security updates are disabled, including for private repositories or across all repositories. Disabling these alerts can prevent detection and remediation of vulnerable or outdated dependencies, reducing an organization’s security visibility. The detection relies on GitHub audit log entries capturing the specific disable actions and the associated actor who performed the change.

Related detections9 linkedT1195.001 — drag to rearrange
Malicious TeamPCP systemd User Unit Dropper via sysmon.py Persistence (via file_event)
Suspicious Python Startup .pth File Creation for Interpreter Persistence
Malicious Backdoored liblzma XZ Utils Library File via file_event
Suspicious SSH Daemon Spawning Shell via xz Backdoor (via process_creation)
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Malicious PyPI Package Installation from Gleaming Pisces Supply Chain (via process_creation)
Malicious TeamPCP LiteLLM .pth Startup Hook and Payload Dropper (via file_event)
Malicious Backdoored liblzma Loaded by sshd (CVE-2024-3094)
Windows file indicators for Octopus Scanner malware artifacts
GitHub Audit: Dependabot Alerts and Security Updates Disabled
Pivot detection · T1195.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.