diff --git a/detections/cloud/github_commit_changes_in_master.yml b/detections/cloud/github_commit_changes_in_master.yml index 73636df24e..309a3a0571 100644 --- a/detections/cloud/github_commit_changes_in_master.yml +++ b/detections/cloud/github_commit_changes_in_master.yml @@ -5,16 +5,18 @@ date: '2021-08-20' author: Teoderick Contreras, Splunk type: Anomaly datamodel: [] -description: This search is to detect a pushed or commit to master or main branch. - This is to avoid unwanted modification to master without a review to the changes. Ideally in terms of devsecops the changes made in a branch and do a - PR for review. of course in some cases admin of the project may did a changes directly to master branch -search: '`github` branches{}.name = main - | stats count min(_time) as firstTime max(_time) as lastTime by commit.author.html_url commit.commit.author.email commit.author.login commit.commit.message repository.pushed_at commit.commit.committer.date - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `github_commit_changes_in_master_filter`' +description: This search is to detect a pushed or commit to master or main branch. + This is to avoid unwanted modification to master without a review to the changes. + Ideally in terms of devsecops the changes made in a branch and do a PR for review. + of course in some cases admin of the project may did a changes directly to master + branch +search: '`github` branches{}.name = main | stats count min(_time) as firstTime max(_time) + as lastTime by commit.author.html_url commit.commit.author.email commit.author.login + commit.commit.message repository.pushed_at commit.commit.committer.date | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `github_commit_changes_in_master_filter`' how_to_implement: To successfully implement this search, you need to be ingesting - logs related to github logs having the fork, commit, push metadata that can be use to monitor the changes in a github project. + logs related to github logs having the fork, commit, push metadata that can be use + to monitor the changes in a github project. known_false_positives: admin can do changes directly to master branch references: - https://www.redhat.com/en/topics/devops/what-is-devsecops @@ -35,8 +37,7 @@ tags: - _time security_domain: endpoint impact: 30 - confidence: 30 - # (impact * confidence)/100 + confidence: 30 risk_score: 9 context: - Source:Endpoint @@ -47,5 +48,4 @@ tags: type: User role: - attacker - - \ No newline at end of file + automated_detection_testing: passed