New GitHub Self Hosted Action Runner
This rule detects the creation of a self-hosted Github runner from a first time seen user.name in the last 5 days. Adversaries may abuse self-hosted runners to execute workflow jobs on customer infrastructure.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2025/11/28"
3integration = ["github"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10This rule detects the creation of a self-hosted Github runner from a first time seen user.name in the last 5 days. Adversaries
11may abuse self-hosted runners to execute workflow jobs on customer infrastructure.
12"""
13false_positives = [
14 "Authorized self-hosted GitHub actions runner.",
15]
16from = "now-9m"
17index = ["logs-github.audit-*"]
18language = "kuery"
19license = "Elastic License v2"
20name = "New GitHub Self Hosted Action Runner"
21note = """## Triage and analysis
22
23### Investigating New GitHub Self Hosted Action Runner
24
25Adversaries who gain the ability to modify or trigger workflows in a linked GitHub repository can execute arbitrary commands on the runner host.
26
27### Possible investigation steps
28
29- Validate the user is authoried to perform this change
30- Review the purpose of the self-hosted action runner and what actions will be executed.
31- Verify if there is any adjascent sensitive file access or collection.
32- Correlate with other alerts and investiguate if this activity is related to a supply chain attack.
33
34### False positive analysis
35
36- Authorized github self-hosted actions runner.
37
38### Response and remediation
39
40- Immediately isolate the affected system from the network to prevent further unauthorized command execution and potential lateral movement.
41- Terminate any suspicious child processes that were initiated by the Github actions runner.
42- Conduct a thorough review of the affected system's logs and configurations to identify any unauthorized changes or additional indicators of compromise.
43- Restore the system from a known good backup if any unauthorized changes or malicious activities are confirmed.
44- Implement application whitelisting to prevent unauthorized execution.
45- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to assess the potential impact on the broader network."""
46references = [
47 "https://www.elastic.co/blog/shai-hulud-worm-npm-supply-chain-compromise",
48 "https://socket.dev/blog/shai-hulud-strikes-again-v2",
49 "https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack"
50]
51risk_score = 47
52rule_id = "40c34c8a-b0bc-43bc-83aa-d2b76bf129e1"
53severity = "medium"
54tags = [
55 "Domain: Cloud",
56 "Use Case: Threat Detection",
57 "Tactic: Initial Access",
58 "Data Source: Github",
59 "Data Source: GitHub Audit Logs",
60 "Resources: Investigation Guide",
61 "Noise: Low",
62 "Performance: Fast",
63 "Profile: Recommended",
64 "Threat: Supply Chain",
65 "Rule Type: New Terms",
66 "Platform: GitHub",
67 "Domain: SaaS",
68]
69timestamp_override = "event.ingested"
70type = "new_terms"
71
72query = '''
73data_stream.dataset:"github.audit" and
74 event.category:"configuration" and
75 event.action: (
76 "repo.register_self_hosted_runner" or
77 "org.register_self_hosted_runner" or
78 "enterprise.register_self_hosted_runner"
79 )
80'''
81
82[[rule.threat]]
83framework = "MITRE ATT&CK"
84
85[[rule.threat.technique]]
86id = "T1195"
87name = "Supply Chain Compromise"
88reference = "https://attack.mitre.org/techniques/T1195/"
89
90[[rule.threat.technique.subtechnique]]
91id = "T1195.001"
92name = "Compromise Software Dependencies and Development Tools"
93reference = "https://attack.mitre.org/techniques/T1195/001/"
94
95[[rule.threat.technique.subtechnique]]
96id = "T1195.002"
97name = "Compromise Software Supply Chain"
98reference = "https://attack.mitre.org/techniques/T1195/002/"
99
100[rule.threat.tactic]
101id = "TA0001"
102name = "Initial Access"
103reference = "https://attack.mitre.org/tactics/TA0001/"
104[rule.new_terms]
105field = "new_terms_fields"
106value = ["user.name", "github.actor_ip"]
107
108[[rule.new_terms.history_window_start]]
109field = "history_window_start"
110value = "now-5d"```
Triage and analysis
Investigating New GitHub Self Hosted Action Runner
Adversaries who gain the ability to modify or trigger workflows in a linked GitHub repository can execute arbitrary commands on the runner host.
Possible investigation steps
- Validate the user is authoried to perform this change
- Review the purpose of the self-hosted action runner and what actions will be executed.
- Verify if there is any adjascent sensitive file access or collection.
- Correlate with other alerts and investiguate if this activity is related to a supply chain attack.
False positive analysis
- Authorized github self-hosted actions runner.
Response and remediation
- Immediately isolate the affected system from the network to prevent further unauthorized command execution and potential lateral movement.
- Terminate any suspicious child processes that were initiated by the Github actions runner.
- Conduct a thorough review of the affected system's logs and configurations to identify any unauthorized changes or additional indicators of compromise.
- Restore the system from a known good backup if any unauthorized changes or malicious activities are confirmed.
- Implement application whitelisting to prevent unauthorized execution.
- Escalate the incident to the security operations center (SOC) or incident response team for further investigation and to assess the potential impact on the broader network.
References
Related rules
- GitHub Actions Workflow Modification Blocked
- GitHub Actions Unusual Bot Push to Repository
- Github Activity on a Private Repository from an Unusual IP
- GitHub Private Repository Turned Public
- GitHub Repository Deleted