GitHub Secret Scanning Push Protection Disabled

Alerts on GitHub audit log events where secret scanning push protection is disabled for org, repo, or custom patterns.

FreeUnreviewedSigmahighv1
title: GitHub Secret Scanning Push Protection Disabled
id: fec59ca6-804f-41f7-9278-1e49b8076fa5
status: test
description: This rule flags audit events indicating that secret scanning push protection has been disabled for an organization, enterprise, repositories, or for custom pattern rules. Attackers may disable this safeguard to allow secrets to be pushed without being blocked, increasing the chance of credential or sensitive data exposure. It relies on GitHub audit log events that record push protection disablement actions across the relevant scopes.
references:
  - https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/push-protection-for-repositories-and-organizations
  - https://thehackernews.com/2024/03/github-rolls-out-default-secret.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/github/audit/github_push_protection_disabled.yml
author: Muhammad Faisal (@faisalusuf), Huntrule Team
date: 2024-03-07
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  product: github
  service: audit
  definition: "Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"
detection:
  selection:
    action:
      - business_secret_scanning_custom_pattern_push_protection.disabled
      - business_secret_scanning_push_protection.disable
      - business_secret_scanning_push_protection.disabled_for_new_repos
      - org.secret_scanning_custom_pattern_push_protection_disabled
      - org.secret_scanning_push_protection_disable
      - org.secret_scanning_push_protection_new_repos_disable
      - repository_secret_scanning_custom_pattern_push_protection.disabled
  condition: selection
falsepositives:
  - Allowed administrative activities.
level: high
license: DRL-1.1
related:
  - id: ccd55945-badd-4bae-936b-823a735d37dd
    type: derived

What it detects

This rule flags audit events indicating that secret scanning push protection has been disabled for an organization, enterprise, repositories, or for custom pattern rules. Attackers may disable this safeguard to allow secrets to be pushed without being blocked, increasing the chance of credential or sensitive data exposure. It relies on GitHub audit log events that record push protection disablement actions across the relevant scopes.

Known false positives

  • Allowed administrative activities.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.