Skip to content

Latest commit

 

History

History
19 lines (17 loc) · 20.4 KB

ds_github_github.md

File metadata and controls

19 lines (17 loc) · 20.4 KB

Vendor: GitHub

Product: GitHub

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
101 39 12 8 58
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Abnormal Authentication & Access user-create:success (account-creation)
github-g-json-app-activity-document_id

app-activity:success (app-activity)
github-g-json-app-activity-success-actorid
github-g-json-app-activity-success-pullrequestreviewcommentcreate
github-g-json-app-activity-success-preparedworkflowjob
github-g-json-app-activity-success-pullrequestcreatereviewrequest
github-g-json-app-activity-success-secretscanningalert
github-g-json-app-activity-success-workflowscompletedworkflowrun
github-g-json-app-activity-success-githubaudit
github-g-json-app-activity-success-workflowscreatedworkflowrun
github-g-kv-app-activity-success-githubunicorn
github-g-json-app-activity-success-apirequest
github-g-json-app-activity-success-integrationinstallation
github-g-json-app-activity-success-pullrequestreviewsubmit
github-g-json-app-activity-success-issuecommentupdate
github-g-json-configuration-create-success-environmentcreate
github-g-json-hook-delete-success-hookdestroy
github-g-json-hook-modify-success-hookconfigchanged
github-g-json-branch-protection-enable-success-protectedbranchcreate
github-g-json-branch-protection-disable-success-protectedbranchdestroy
github-g-json-user-invite-success-org
github-g-json-http-request-success-githubaudithook
github-g-json-repository-create-success-gitclone
github-g-sk4-repository-create-success-createevent
github-g-json-repository-create-success-githubauditrepo
github-g-csv-repository-create-success-projectcreate
github-g-csv-repository-modify-success-update
github-g-json-user-create-success-githubauditteam
github-g-kv-app-activity-controller
github-g-json-app-activity-success-namespaceid
github-g-kv-http-request-api
github-g-kv-http-request-githubunicorn
github-g-json-app-activity-document_id
github-g-json-app-activity-document_id
github-g-json-app-activity-document_id
github-g-json-app-activity-success-pullrequest
github-g-json-app-activity-success-issuecommentdestroy
github-g-sk4-repository-create-success-github
github-g-json-app-activity-success-workflows
github-g-json-app-activity-success-team
github-g-json-app-activity-success-org
github-g-json-branch-modify-success-pullrequestmerge
github-g-json-branch-modify-success-pullrequestindirectmerge
github-g-json-repository-push-success-gitpush
github-g-sk4-repository-push-success-pushevent
github-g-json-repository-pull-success-gitfetch
github-g-sk4-repository-pull-success-pullrequestevent
github-g-json-repository-pull-success-repodownloadzip
github-g-json-branch-create-success-pullrequestcreate
github-g-sk4-repository-member-add-success-memberevent
github-g-json-repository-member-add-success-teamaddmember
github-g-sk4-repository-delete-success-deleteevent
github-g-json-hook-create-success-repocreate
github-g-json-repository-create-success-repocreate
github-g-json-key-read-success-publickeyverify
github-g-json-key-create-success-publickeycreate
github-g-json-key-delete-success-publickeydelete
github-g-json-branch-protection-modify-success-policyoverride
github-g-json-branch-protection-modify-success-protectedbranchupdateadminenforced
github-g-json-branch-protection-modify-success-protectedbranchupdate
github-g-json-repository-modify-success-repo
github-g-json-repository-modify-success-repo

app-login:success (app-login)
github-g-kv-app-login-authentication
github-g-json-app-activity-document_id

vpn-login:fail (authentication-failed)
github-g-json-app-authentication-fail-authorizationdeauthorize

vpn-authentication:success (authentication-successful)
github-g-json-app-authentication-success-authorizationgrant
github-g-json-app-authentication-success-accessgranted
github-g-kv-app-authentication-success-gitauth
github-g-json-app-authentication-success-orgssoresponse
github-g-json-app-authentication-success-businessssoresponse

app-login:fail (failed-app-login)
github-g-kv-app-login-authentication
github-g-json-app-login-fail-failedlogin

group-member-remove:success (member-removed)
github-g-json-group-member-remove-success-teamremovemember
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Account Manipulation user-create:success (account-creation)
github-g-json-app-activity-document_id

app-activity:success (app-activity)
github-g-json-app-activity-success-actorid
github-g-json-app-activity-success-pullrequestreviewcommentcreate
github-g-json-app-activity-success-preparedworkflowjob
github-g-json-app-activity-success-pullrequestcreatereviewrequest
github-g-json-app-activity-success-secretscanningalert
github-g-json-app-activity-success-workflowscompletedworkflowrun
github-g-json-app-activity-success-githubaudit
github-g-json-app-activity-success-workflowscreatedworkflowrun
github-g-kv-app-activity-success-githubunicorn
github-g-json-app-activity-success-apirequest
github-g-json-app-activity-success-integrationinstallation
github-g-json-app-activity-success-pullrequestreviewsubmit
github-g-json-app-activity-success-issuecommentupdate
github-g-json-configuration-create-success-environmentcreate
github-g-json-hook-delete-success-hookdestroy
github-g-json-hook-modify-success-hookconfigchanged
github-g-json-branch-protection-enable-success-protectedbranchcreate
github-g-json-branch-protection-disable-success-protectedbranchdestroy
github-g-json-user-invite-success-org
github-g-json-http-request-success-githubaudithook
github-g-json-repository-create-success-gitclone
github-g-sk4-repository-create-success-createevent
github-g-json-repository-create-success-githubauditrepo
github-g-csv-repository-create-success-projectcreate
github-g-csv-repository-modify-success-update
github-g-json-user-create-success-githubauditteam
github-g-kv-app-activity-controller
github-g-json-app-activity-success-namespaceid
github-g-kv-http-request-api
github-g-kv-http-request-githubunicorn
github-g-json-app-activity-document_id
github-g-json-app-activity-document_id
github-g-json-app-activity-document_id
github-g-json-app-activity-success-pullrequest
github-g-json-app-activity-success-issuecommentdestroy
github-g-sk4-repository-create-success-github
github-g-json-app-activity-success-workflows
github-g-json-app-activity-success-team
github-g-json-app-activity-success-org
github-g-json-branch-modify-success-pullrequestmerge
github-g-json-branch-modify-success-pullrequestindirectmerge
github-g-json-repository-push-success-gitpush
github-g-sk4-repository-push-success-pushevent
github-g-json-repository-pull-success-gitfetch
github-g-sk4-repository-pull-success-pullrequestevent
github-g-json-repository-pull-success-repodownloadzip
github-g-json-branch-create-success-pullrequestcreate
github-g-sk4-repository-member-add-success-memberevent
github-g-json-repository-member-add-success-teamaddmember
github-g-sk4-repository-delete-success-deleteevent
github-g-json-hook-create-success-repocreate
github-g-json-repository-create-success-repocreate
github-g-json-key-read-success-publickeyverify
github-g-json-key-create-success-publickeycreate
github-g-json-key-delete-success-publickeydelete
github-g-json-branch-protection-modify-success-policyoverride
github-g-json-branch-protection-modify-success-protectedbranchupdateadminenforced
github-g-json-branch-protection-modify-success-protectedbranchupdate
github-g-json-repository-modify-success-repo
github-g-json-repository-modify-success-repo

group-member-remove:success (member-removed)
github-g-json-group-member-remove-success-teamremovemember
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
  • 37 Rules
  • 15 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Create Account

External Remote Services

Valid Accounts

Account Manipulation

Create Account: Create: Local Account

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Valid Accounts

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy