name: GitHub Dependabot Alert id: 05032b04-4469-4034-9df7-05f607d75cba version: 1 date: '2021-09-01' author: Patrick Bareiss, Splunk type: Anomaly datamodel: [] description: This search looks for Dependabot Alerts in Github logs. search: '`github` alert.id=* action=create | rename repository.full_name as repository, repository.html_url as repository_url sender.login as user | stats min(_time) as firstTime max(_time) as lastTime by action alert.affected_package_name alert.affected_range alert.created_at alert.external_identifier alert.external_reference alert.fixed_in alert.severity repository repository_url user | eval phase="code" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `github_dependabot_alert_filter`' how_to_implement: You must index GitHub logs. You can follow the url in reference to onboard GitHub logs. known_false_positives: unknown references: - https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html tags: analytic_story: - Dev Sec Ops asset_type: GitHub cis20: - CIS 13 confidence: 90 context: - Source:Application Log - Stage:Discovery dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_security_advisor_alert/github_security_advisor_alert.json impact: 30 kill_chain_phases: - Actions on Objectives message: Vulnerabilities found in packages used by GitHub repository $repository$ mitre_attack_id: - T1195.001 - T1195 nist: - PR.DS - PR.AC - DE.CM observable: - name: repository type: Unknown role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - alert.id - repository.full_name - repository.html_url - action - alert.affected_package_name - alert.affected_range - alert.created_at - alert.external_identifier - alert.external_reference - alert.fixed_in - alert.severity risk_score: 27 security_domain: network