
Summary
This detection rule alerts on unauthorized access attempts to resources within Bitbucket, specifically targeting actions categorized under security violations. It operates by monitoring audit logs for entries where the action is listed as 'Unauthorized access to a resource'. This is crucial for protecting repositories against unauthorized use or attempts to gain access to private data. To successfully capture these events, it is essential for the logging level to be set to 'Advance', which enables comprehensive auditing of significant security-related actions. The rule helps security teams identify potentially malicious actors trying to exploit weaknesses in access controls, thereby supporting better incident response efforts and security postures.
Categories
- Cloud
- Web
- Application
Data Sources
- User Account
- Application Log
Created: 2024-02-25