-
GitHub Actions Unusual Bot Push to Repository
Sep 19, 2026 · Domain: Cloud Use Case: Threat Detection Tactic: Initial Access Tactic: Persistence Data Source: Github Data Source: GitHub Audit Logs Resources: Investigation Guide Noise: Medium Performance: Fast Threat: Supply Chain Rule Type: New Terms Platform: GitHub Domain: SaaS Service: GitHub Actions ·Detects when the github-actions[bot] pushes code to a repository where it has not performed this behavior before in a certain time window. This may indicate a supply chain attack where malicious code running in a CI workflow attempts to modify repository contents, such as injecting backdoor workflow files.
Read More -
GitHub Actions Workflow Modification Blocked
Sep 19, 2026 · Domain: Cloud Use Case: Threat Detection Tactic: Initial Access Tactic: Persistence Tactic: Execution Data Source: Github Data Source: GitHub Audit Logs Resources: Investigation Guide Noise: Low Performance: Fast Profile: Recommended Threat: Supply Chain Rule Type: ES|QL Platform: GitHub Domain: SaaS Service: GitHub Actions ·Detects when a GitHub Actions workflow attempts to create or modify workflow files in a protected branch but is blocked due to insufficient permissions. This behavior is indicative of a supply chain attack where a malicious package or compromised CI/CD pipeline attempts to inject persistent backdoor workflows into a repository.
Read More