OpenCanary Git Service: Git Clone Request Observed

Flags OpenCanary Git service logs showing a Git clone request, indicating possible repository access attempts.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags OpenCanary events indicating a Git service on an OpenCanary node received a Git Clone request. Git clone activity can represent reconnaissance or attempts to obtain repository contents from exposed services. The detection relies on OpenCanary application telemetry where Git service requests are logged, specifically matching the event logtype associated with clone requests.

Related detections7 linkedT1213 — drag to rearrange
Suspicious Snowflake Anomalous Client Application Associated With UNC5537 (via cloud)
OpenCanary MSSQL SQLAuth Login Attempt Detected (logtype 9001)
OpenCanary Redis Action Command Attempt
OpenCanary: MSSQL Windows Authentication Login Attempt (Logtype 9002)
OpenCanary MySQL Service: Login Attempt Recorded
Bitbucket Audit: User Permissions Export Attempt Detection
Bitbucket Audit: User Permission Details Export Attempts
OpenCanary Git Service: Git Clone Request Observed
Pivot detection · T1213 · 7 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.