Vendor: GitHub

November 29, 2023 · View on GitHub

Product: GitHub

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
10243955
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessapp-activity
github-g-json-app-activity-success-actorid
github-g-json-app-activity-success-preparedworkflowjob
github-g-json-app-activity-success-pullrequestcreatereviewrequest
github-g-json-app-activity-success-secretscanningalert
github-g-json-app-activity-success-workflowscompletedworkflowrun
github-g-json-app-activity-success-githubaudit
github-g-json-app-activity-success-apirequest
github-g-json-app-activity-success-integrationinstallation
github-g-json-app-activity-success-issuecommentupdate
github-g-json-app-activity-success-workflowscreatedworkflowrun
github-g-json-configuration-create-success-environmentcreate
github-g-json-hook-delete-success-hookdestroy
github-g-json-hook-modify-success-hookconfigchanged
github-g-json-user-invite-success-org
github-g-json-http-request-success-githubaudithook
github-g-sk4-repository-create-success-createevent
github-g-json-repository-create-success-githubauditrepo
github-g-csv-repository-create-success-projectcreate
github-g-json-user-create-success-githubauditteam
github-g-kv-app-activity-controller
github-g-kv-http-request-api
github-g-json-app-activity-success-issuecommentdestroy
github-g-sk4-repository-create-success-github
github-g-json-branch-modify-success-pullrequestmerge
github-g-json-branch-modify-success-pullrequestindirectmerge
github-g-sk4-repository-push-success-pushevent
github-g-sk4-repository-pull-success-pullrequestevent
github-g-json-repository-pull-success-repodownloadzip
github-g-json-branch-create-success-pullrequestcreate
github-g-sk4-repository-member-add-success-memberevent
github-g-json-repository-member-add-success-teamaddmember
github-g-sk4-repository-delete-success-deleteevent
github-g-json-key-read-success-publickeyverify
github-g-json-key-create-success-publickeycreate
github-g-json-key-delete-success-publickeydelete

authentication-failed
github-g-json-app-authentication-fail-accessrevoked
github-g-json-app-authentication-fail-authorizationdeauthorize

authentication-successful
github-g-json-app-authentication-success-authorizationgrant
github-g-json-app-authentication-success-accessgranted
github-g-json-app-authentication-success-businessssoresponse
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Account Manipulationapp-activity
github-g-json-app-activity-success-actorid
github-g-json-app-activity-success-preparedworkflowjob
github-g-json-app-activity-success-pullrequestcreatereviewrequest
github-g-json-app-activity-success-secretscanningalert
github-g-json-app-activity-success-workflowscompletedworkflowrun
github-g-json-app-activity-success-githubaudit
github-g-json-app-activity-success-apirequest
github-g-json-app-activity-success-integrationinstallation
github-g-json-app-activity-success-issuecommentupdate
github-g-json-app-activity-success-workflowscreatedworkflowrun
github-g-json-configuration-create-success-environmentcreate
github-g-json-hook-delete-success-hookdestroy
github-g-json-hook-modify-success-hookconfigchanged
github-g-json-user-invite-success-org
github-g-json-http-request-success-githubaudithook
github-g-sk4-repository-create-success-createevent
github-g-json-repository-create-success-githubauditrepo
github-g-csv-repository-create-success-projectcreate
github-g-json-user-create-success-githubauditteam
github-g-kv-app-activity-controller
github-g-kv-http-request-api
github-g-json-app-activity-success-issuecommentdestroy
github-g-sk4-repository-create-success-github
github-g-json-branch-modify-success-pullrequestmerge
github-g-json-branch-modify-success-pullrequestindirectmerge
github-g-sk4-repository-push-success-pushevent
github-g-sk4-repository-pull-success-pullrequestevent
github-g-json-repository-pull-success-repodownloadzip
github-g-json-branch-create-success-pullrequestcreate
github-g-sk4-repository-member-add-success-memberevent
github-g-json-repository-member-add-success-teamaddmember
github-g-sk4-repository-delete-success-deleteevent
github-g-json-key-read-success-publickeyverify
github-g-json-key-create-success-publickeycreate
github-g-json-key-delete-success-publickeydelete
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Account Manipulation

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Valid Accounts

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy