
Summary
The 'Risk Rule for Dev Sec Ops by Repository' is designed to identify high-risk activities within repositories by correlating repository data with associated risk scores. This analytic process taps into the Dev Sec Ops analytic stories, summarizing risk events to calculate an overall risk score. The detection mechanism is set to trigger alerts for repositories exhibiting risk scores exceeding 100 and displaying more than three instances of risky source activity. By targeting these high-risk repositories, organizations can gain crucial insights into potential vulnerabilities, which could be avenues for attack leading to data breaches or infrastructure compromise. The rule utilizes advanced searches to collate relevant data and aggregates various risk indicators to highlight significant threats, ensuring timely awareness of repository security status.
Categories
- Cloud
- Infrastructure
- Application
- Containers
Data Sources
- Container
- Application Log
- Cloud Service
ATT&CK Techniques
- T1204.003
- T1204
Created: 2024-11-14