Github Activity on a Private Repository from an Unusual IP

Detects when there is activity on a private GitHub repository from an unusual IP address. Adversaries may access private repositories from unfamiliar IPs to exfiltrate sensitive code or data, potentially indicating a compromise or unauthorized access.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2025/12/16"
  3integration = ["github"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects when there is activity on a private GitHub repository from an unusual IP address. Adversaries may
 11access private repositories from unfamiliar IPs to exfiltrate sensitive code or data, potentially indicating
 12a compromise or unauthorized access.
 13"""
 14from = "now-9m"
 15index = ["logs-github.audit-*"]
 16language = "kuery"
 17license = "Elastic License v2"
 18name = "Github Activity on a Private Repository from an Unusual IP"
 19references = [
 20    "https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack",
 21    "https://trigger.dev/blog/shai-hulud-postmortem",
 22    "https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem",
 23]
 24risk_score = 21
 25rule_id = "daf2e0e0-0bab-4672-bfa1-62db0ee5ec22"
 26severity = "low"
 27tags = [
 28    "Domain: Cloud",
 29    "Use Case: Threat Detection",
 30    "Tactic: Impact",
 31    "Tactic: Initial Access",
 32    "Tactic: Persistence",
 33    "Data Source: Github",
 34    "Data Source: GitHub Audit Logs",
 35    "Resources: Investigation Guide",
 36    "Noise: High",
 37    "Performance: Fast",
 38    "Profile: Aggressive",
 39    "Threat: Supply Chain",
 40    "Rule Type: New Terms",
 41    "Platform: GitHub",
 42    "Domain: SaaS",
 43]
 44timestamp_override = "event.ingested"
 45type = "new_terms"
 46query = '''
 47data_stream.dataset:"github.audit" and event.action:("git.push" or "git.clone") and github.repository_public:false
 48'''
 49
 50[[rule.threat]]
 51framework = "MITRE ATT&CK"
 52
 53[rule.threat.tactic]
 54id = "TA0040"
 55name = "Impact"
 56reference = "https://attack.mitre.org/tactics/TA0040/"
 57
 58[[rule.threat]]
 59framework = "MITRE ATT&CK"
 60
 61[[rule.threat.technique]]
 62id = "T1078"
 63name = "Valid Accounts"
 64reference = "https://attack.mitre.org/techniques/T1078/"
 65
 66[[rule.threat.technique.subtechnique]]
 67id = "T1078.004"
 68name = "Cloud Accounts"
 69reference = "https://attack.mitre.org/techniques/T1078/004/"
 70
 71[[rule.threat.technique]]
 72id = "T1195"
 73name = "Supply Chain Compromise"
 74reference = "https://attack.mitre.org/techniques/T1195/"
 75
 76[[rule.threat.technique.subtechnique]]
 77id = "T1195.002"
 78name = "Compromise Software Supply Chain"
 79reference = "https://attack.mitre.org/techniques/T1195/002/"
 80
 81[rule.threat.tactic]
 82id = "TA0001"
 83name = "Initial Access"
 84reference = "https://attack.mitre.org/tactics/TA0001/"
 85
 86[[rule.threat]]
 87framework = "MITRE ATT&CK"
 88
 89[[rule.threat.technique]]
 90id = "T1059"
 91name = "Command and Scripting Interpreter"
 92reference = "https://attack.mitre.org/techniques/T1059/"
 93
 94[rule.threat.tactic]
 95id = "TA0002"
 96name = "Execution"
 97reference = "https://attack.mitre.org/tactics/TA0002/"
 98
 99[[rule.threat]]
100framework = "MITRE ATT&CK"
101
102[[rule.threat.technique]]
103id = "T1213"
104name = "Data from Information Repositories"
105reference = "https://attack.mitre.org/techniques/T1213/"
106
107[[rule.threat.technique.subtechnique]]
108id = "T1213.003"
109name = "Code Repositories"
110reference = "https://attack.mitre.org/techniques/T1213/003/"
111
112[rule.threat.tactic]
113id = "TA0009"
114name = "Collection"
115reference = "https://attack.mitre.org/tactics/TA0009/"
116[rule.new_terms]
117field = "new_terms_fields"
118value = ["source.ip", "github.repo"]
119
120[[rule.new_terms.history_window_start]]
121field = "history_window_start"
122value = "now-7d"

References

Related rules

to-top