{"id":"34d81081-03c9-4a7f-91c9-5e46af625cde","title":"Bitbucket Unauthorized Full Data Export Triggered","description":"Detects when full data export is attempted an unauthorized user.","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"critical","date":"2024-02-25","modified":"","tags":["attack.collection","attack.resource-development","attack.t1213.003","attack.t1586"],"technique_ids":["T1213.003","T1586"],"logsource":{"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."},"falsepositives":["Unlikely"],"references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html"],"source_path":"rules/application/bitbucket/audit/bitbucket_audit_unauthorized_full_data_export_triggered.yml","source_sha256":"4bd0160241f2fba2f3bba2f2f0b75a6ac7db0e8075bd764582d3ee257d448559","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/bitbucket/audit/bitbucket_audit_unauthorized_full_data_export_triggered.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Bitbucket Unauthorized Full Data Export Triggered\nid: 34d81081-03c9-4a7f-91c9-5e46af625cde\nstatus: test\ndescription: Detects when full data export is attempted an unauthorized user.\nreferences:\n    - https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html\n    - https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html\nauthor: Muhammad Faisal (@faisalusuf)\ndate: 2024-02-25\ntags:\n    - attack.collection\n    - attack.resource-development\n    - attack.t1213.003\n    - attack.t1586\nlogsource:\n    product: bitbucket\n    service: audit\n    definition: 'Requirements: \"Advance\" log level is required to receive these audit events.'\ndetection:\n    selection:\n        auditType.category: 'Data pipeline'\n        auditType.action: 'Unauthorized full data export triggered'\n    condition: selection\nfalsepositives:\n    - Unlikely\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1213.003","id":"T1213.003","name":"Code Repositories","page":"techniques/enterprise/T1213.003/"},{"key":"enterprise/T1586","id":"T1586","name":"Compromise Accounts","page":"techniques/enterprise/T1586/"}],"data_path":"data/detection-rules/34d81081-03c9-4a7f-91c9-5e46af625cde.json","kind":"sigma"}
