Github Activity on a Private Repository from an Unusual IP
Detects when there is activity on a private GitHub repository from an unusual IP address. Adversaries may access private repositories from unfamiliar IPs to exfiltrate sensitive code or data, potentially indicating a compromise or unauthorized access.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2025/12/16"
3integration = ["github"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Detects when there is activity on a private GitHub repository from an unusual IP address. Adversaries may
11access private repositories from unfamiliar IPs to exfiltrate sensitive code or data, potentially indicating
12a compromise or unauthorized access.
13"""
14from = "now-9m"
15index = ["logs-github.audit-*"]
16language = "kuery"
17license = "Elastic License v2"
18name = "Github Activity on a Private Repository from an Unusual IP"
19references = [
20 "https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack",
21 "https://trigger.dev/blog/shai-hulud-postmortem",
22 "https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem",
23]
24risk_score = 21
25rule_id = "daf2e0e0-0bab-4672-bfa1-62db0ee5ec22"
26severity = "low"
27tags = [
28 "Domain: Cloud",
29 "Use Case: Threat Detection",
30 "Tactic: Impact",
31 "Tactic: Initial Access",
32 "Tactic: Persistence",
33 "Data Source: Github",
34 "Data Source: GitHub Audit Logs",
35 "Resources: Investigation Guide",
36 "Noise: High",
37 "Performance: Fast",
38 "Profile: Aggressive",
39 "Threat: Supply Chain",
40 "Rule Type: New Terms",
41 "Platform: GitHub",
42 "Domain: SaaS",
43]
44timestamp_override = "event.ingested"
45type = "new_terms"
46query = '''
47data_stream.dataset:"github.audit" and event.action:("git.push" or "git.clone") and github.repository_public:false
48'''
49
50[[rule.threat]]
51framework = "MITRE ATT&CK"
52
53[rule.threat.tactic]
54id = "TA0040"
55name = "Impact"
56reference = "https://attack.mitre.org/tactics/TA0040/"
57
58[[rule.threat]]
59framework = "MITRE ATT&CK"
60
61[[rule.threat.technique]]
62id = "T1078"
63name = "Valid Accounts"
64reference = "https://attack.mitre.org/techniques/T1078/"
65
66[[rule.threat.technique.subtechnique]]
67id = "T1078.004"
68name = "Cloud Accounts"
69reference = "https://attack.mitre.org/techniques/T1078/004/"
70
71[[rule.threat.technique]]
72id = "T1195"
73name = "Supply Chain Compromise"
74reference = "https://attack.mitre.org/techniques/T1195/"
75
76[[rule.threat.technique.subtechnique]]
77id = "T1195.002"
78name = "Compromise Software Supply Chain"
79reference = "https://attack.mitre.org/techniques/T1195/002/"
80
81[rule.threat.tactic]
82id = "TA0001"
83name = "Initial Access"
84reference = "https://attack.mitre.org/tactics/TA0001/"
85
86[[rule.threat]]
87framework = "MITRE ATT&CK"
88
89[[rule.threat.technique]]
90id = "T1059"
91name = "Command and Scripting Interpreter"
92reference = "https://attack.mitre.org/techniques/T1059/"
93
94[rule.threat.tactic]
95id = "TA0002"
96name = "Execution"
97reference = "https://attack.mitre.org/tactics/TA0002/"
98
99[[rule.threat]]
100framework = "MITRE ATT&CK"
101
102[[rule.threat.technique]]
103id = "T1213"
104name = "Data from Information Repositories"
105reference = "https://attack.mitre.org/techniques/T1213/"
106
107[[rule.threat.technique.subtechnique]]
108id = "T1213.003"
109name = "Code Repositories"
110reference = "https://attack.mitre.org/techniques/T1213/003/"
111
112[rule.threat.tactic]
113id = "TA0009"
114name = "Collection"
115reference = "https://attack.mitre.org/tactics/TA0009/"
116[rule.new_terms]
117field = "new_terms_fields"
118value = ["source.ip", "github.repo"]
119
120[[rule.new_terms.history_window_start]]
121field = "history_window_start"
122value = "now-7d"
References
Related rules
- GitHub Actions Unusual Bot Push to Repository
- GitHub Actions Workflow Modification Blocked
- New GitHub Self Hosted Action Runner
- GitHub App Deleted
- GitHub Protected Branch Settings Changed