heroui logo

Circle CI Disable Security Step

Splunk Security Content

View Source
Summary
This analytic detects the disabling of security steps within CircleCI pipelines, leveraging CircleCI logs for monitoring deviations from expected security protocols. The method incorporates field renaming, joining of datasets, and statistical evaluations to identify moments when critical security phases are bypassed. The disabling of mandated security steps poses a substantial risk as it can lead to vulnerabilities, unauthorized adjustments, or the introduction of malicious code, potentially leading to data breaches or severe infrastructure compromise. Security teams are urged to investigate any instances where security measures are removed, analyzing job names, commit details, and associated user information to determine the legitimacy of such actions. Corresponding artifacts and concurrent processes should also be examined to provide comprehensive risk assessments regarding the practices adopted within the CI/CD workflows.
Categories
  • Cloud
  • Infrastructure
Data Sources
  • Cloud Service
  • Application Log
ATT&CK Techniques
  • T1554
Created: 2024-11-14