Bitbucket Unauthorized Access To A Resource

 Original Source: [Sigma source]
Title: Bitbucket Unauthorized Access To A Resource
Status: test
Description:Detects unauthorized access attempts to a resource.
References:
  -https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html
Author: Muhammad Faisal (@faisalusuf)
Date: 2024-02-25
modified:None
Tags:
  • -'attack.resource-development'
  • -'attack.t1586'
Logsource:
  • product: bitbucket
  • service: audit
  • definition: Requirements: "Advance" log level is required to receive these audit events.
Detection:
  selection:
    auditType.category: 'Security'
    auditType.action: 'Unauthorized access to a resource'
  condition:selection
Falsepositives:
  -Access attempts to non-existent repositories or due to outdated plugins. Usually "Anonymous" user is reported in the "author.name" field in most cases.
Level: critical