Techniques › T1213 › T1213.003
T1213.003 Code Repositories
collection — SaaS · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
5
Sigma rules tagged attack.t1213.003
0
KEV CVEs mapped here
<p>Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.</p><p>Once adversaries gain access to a victim network or a private code repository, they may collect sensitive information such as proprietary source code or Unsecured Credentials contained within software's source code. Having access to software's source code may allow adversaries to develop Exploits, while credentials may provide access to additional resources using Valid Accounts.</p><p>Note: This is distinct from Code Repositories, which focuses on conducting Reconnaissance via public code repositories.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0263 Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms v1.0
AN0732 SaaSAnomalous or bulk download activity from private or restricted repositories by non-developer or privileged accounts, often preceded by unusual login behavior (e.g., unfamiliar geo, OAuth token use, elevated API rate).saas:github
repo.download, repo.clone, oauth.authorize, repo.getContent→ DC0070 Cloud Service Metadatasaas:githubLogin from unusual IP, device fingerprint, or location; access token creation from new client→ DC0067 Logon Session Creationsaas:githubBulk access to multiple files or large volume of repo requests within short time window→ DC0038 Application Log ContentTunable:TimeWindowUserContextGeoAnomalyThresholdRepoSensitivityTag
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1213.003
Author: Muhammad Faisal (@faisalusuf)
· 2023-01-19 (modified 2026-03-09) · logsource: product=github service=audit · 16a71777-0b2e-4db7-9888-9d59cb75200b
Detects delete action in the Github audit logs for codespaces, environment, project and repo.
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 195e1b9d-bfc2-4ffa-ab4e-35aef69815f8
Detects when full data export is attempted.
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 34d81081-03c9-4a7f-91c9-5e46af625cde
Detects when full data export is attempted an unauthorized user.
Author: Muhammad Faisal (@faisalusuf)
· 2023-01-20 · logsource: product=github service=audit · eaa9ac35-1730-441f-9587-25767bde99d7
Detects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an owner removes an outside collaborator from an organization or when two-factor authentication is required in an organization and an outside collaborator does not use 2FA or disables 2FA.
Author: Muhammad Faisal (@faisalusuf)
· 2023-01-27 · logsource: product=github service=audit · f8ed0e8f-7438-4b79-85eb-f358ef2fbebd
A self-hosted runner is a system that you deploy and manage to execute jobs from GitHub Actions on GitHub.com.
This rule detects changes to self-hosted runners configurations in the environment. The self-hosted runner configuration changes once detected,
it should be validated from GitHub UI because the log entry may not provide full context.
Rules tagged at the parent level (attack.t1213) 7
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 3ec9a16d-0b4f-4967-9542-ebf38ceac7dd
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 4fe17521-aef3-4e6a-9d6b-4a7c8de155a8
Detects instances where a GIT service on an OpenCanary node has had Git Clone request.
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 5259cbf2-0a75-48bf-b57a-c54d6fabaef3
Detects user data export activity.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 547dfc53-ebf6-4afe-8d2e-793d9574975d
Detects instances where a REDIS service on an OpenCanary node has had an action command attempted.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 6e78f90f-0043-4a01-ac41-f97681613a66
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using Windows Authentication.
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 87cc6698-3e07-4ba2-9b43-a85a73e151e2
Detects user permission data export attempt.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · e7d79a1b-25ed-4956-bd56-bd344fa8fd06
Detects instances where a MySQL service on an OpenCanary node has had a login attempt.