
Summary
The GitHub Organizations Delete Branch Ruleset detection rule monitors GitHub Organizations audit logs for events where branch ruleset deletions occur. This is crucial for ensuring security as branch rulesets enforce essential practices such as code reviews, preventing force pushes, and ensuring code quality. Disabling these rules can allow malicious users to push unauthorized changes, which could relate to broader attacks aiming for code disruption. The rule utilizes the GitHub Organizations audit logs as a data source, looking for specific actions (repository_ruleset.destroy) that indicate deletions of branch rulesets and capturing relevant actor and repository data. The analysis provides insights into potential unauthorized behavior that may compromise code integrity and security review processes, signaling threats to the software supply chain.
Categories
- Cloud
- Application
- Identity Management
Data Sources
- Pod
- Container
- User Account
- Application Log
ATT&CK Techniques
- T1562.001
- T1195
Created: 2025-01-17