name: GitHub Pull Request from Unknown User id: 9d7b9100-8878-4404-914e-ca5e551a641e version: 1 date: '2021-09-01' author: Patrick Bareiss, Splunk status: production type: Anomaly description: This search looks for Pull Request from unknown user. data_source: [] search: '`github` check_suite.pull_requests{}.id=* | stats count by check_suite.head_commit.author.name repository.full_name check_suite.pull_requests{}.head.ref check_suite.head_commit.message | rename check_suite.head_commit.author.name as user repository.full_name as repository check_suite.pull_requests{}.head.ref as ref_head check_suite.head_commit.message as commit_message | search NOT `github_known_users` | eval phase="code" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `github_pull_request_from_unknown_user_filter`' how_to_implement: You must index GitHub logs. You can follow the url in reference to onboard GitHub logs. known_false_positives: unknown references: - https://www.splunk.com/en_us/blog/tips-and-tricks/getting-github-data-with-webhooks.html tags: analytic_story: - Dev Sec Ops asset_type: GitHub confidence: 90 impact: 30 message: Vulnerabilities found in packages used by GitHub repository $repository$ mitre_attack_id: - T1195.001 - T1195 observable: - name: repository type: Unknown role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - alert.id - repository.full_name - repository.html_url - action - alert.affected_package_name - alert.affected_range - alert.created_at - alert.external_identifier - alert.external_reference - alert.fixed_in - alert.severity risk_score: 27 security_domain: network tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.001/github_pull_request/github_pull_request.json sourcetype: aws:firehose:json source: github