{"id":"0c46d4f4-a2bf-4104-9597-8d653fc2bb55","title":"GitHub Repository Pages Site Changed to Public","description":"Detects when a GitHub Pages site of a repository is made public. This usually is part of a publishing process but could indicate or lead to potential unauthorized exposure of sensitive information or code.\n","author":"Ivan Saakov","status":"experimental","level":"low","date":"2025-10-18","modified":"","tags":["attack.collection","attack.exfiltration","attack.t1567.001"],"technique_ids":["T1567.001"],"logsource":{"product":"github","service":"audit"},"falsepositives":["Legitimate publishing of repository pages by authorized users"],"references":["https://docs.github.com/en/pages/getting-started-with-github-pages/creating-a-github-pages-site","https://www.sentinelone.com/blog/exploiting-repos-6-ways-threat-actors-abuse-github-other-devops-platforms","https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/security-log-events"],"source_path":"rules/application/github/audit/github_pages_site_changed_to_public.yml","source_sha256":"f33efe94c90ac3d567e72fdc7e0374b1c80a79180a57c01ef63822d4e1a40f22","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/github/audit/github_pages_site_changed_to_public.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: GitHub Repository Pages Site Changed to Public\nid: 0c46d4f4-a2bf-4104-9597-8d653fc2bb55\nstatus: experimental\ndescription: |\n    Detects when a GitHub Pages site of a repository is made public. This usually is part of a publishing process but could indicate or lead to potential unauthorized exposure of sensitive information or code.\nreferences:\n    - https://docs.github.com/en/pages/getting-started-with-github-pages/creating-a-github-pages-site\n    - https://www.sentinelone.com/blog/exploiting-repos-6-ways-threat-actors-abuse-github-other-devops-platforms\n    - https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/security-log-events\nauthor: Ivan Saakov\ndate: 2025-10-18\ntags:\n    - attack.collection\n    - attack.exfiltration\n    - attack.t1567.001\nlogsource:\n    product: github\n    service: audit\ndetection:\n    selection:\n        action: 'repo.pages_public'\n    condition: selection\nfalsepositives:\n    - Legitimate publishing of repository pages by authorized users\nlevel: low\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1567.001","id":"T1567.001","name":"Exfiltration to Code Repository","page":"techniques/enterprise/T1567.001/"}],"data_path":"data/detection-rules/0c46d4f4-a2bf-4104-9597-8d653fc2bb55.json","kind":"sigma"}
