This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
GitHub Repository Pages Site Changed to Public
Original Source:
[Sigma source]
Title:
GitHub Repository Pages Site Changed to Public
Status:
experimental
Description:
Detects when a GitHub Pages site of a repository is made public. This usually is part of a publishing process but could indicate or lead to potential unauthorized exposure of sensitive information or code.
References:
-https://docs.github.com/en/pages/getting-started-with-github-pages/creating-a-github-pages-site
-https://www.sentinelone.com/blog/exploiting-repos-6-ways-threat-actors-abuse-github-other-devops-platforms
-https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/security-log-events
Author:
Ivan Saakov
Date:
2025-10-18
modified:
None
Tags:
-'attack.collection'
-'attack.exfiltration'
-'attack.t1567.001'
Logsource:
product: github
service: audit
Detection:
selection:
action
:
'repo.pages_public'
condition
:
selection
Falsepositives:
-Legitimate publishing of repository pages by authorized users
Level:
low