{"id":"34e1c7d4-0cd5-419d-9f1b-1dad3f61018d","title":"Outdated Dependency Or Vulnerability Alert Disabled","description":"Dependabot performs a scan to detect insecure dependencies, and sends Dependabot alerts.\nThis rule detects when an organization owner disables Dependabot alerts private repositories or Dependabot security updates for all repositories.\n","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"high","date":"2023-01-27","modified":"","tags":["attack.initial-access","attack.t1195.001"],"technique_ids":["T1195.001"],"logsource":{"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"},"falsepositives":["Approved changes by the Organization owner. Please validate the 'actor' if authorized to make the changes."],"references":["https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts","https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-security-and-analysis-settings-for-your-organization"],"source_path":"rules/application/github/audit/github_disabled_outdated_dependency_or_vulnerability.yml","source_sha256":"da09ffd8452b69ffea282e97be666ec5e6026f194c4485da86a52829b56bf7d2","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/github/audit/github_disabled_outdated_dependency_or_vulnerability.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Outdated Dependency Or Vulnerability Alert Disabled\nid: 34e1c7d4-0cd5-419d-9f1b-1dad3f61018d\nstatus: test\ndescription: |\n    Dependabot performs a scan to detect insecure dependencies, and sends Dependabot alerts.\n    This rule detects when an organization owner disables Dependabot alerts private repositories or Dependabot security updates for all repositories.\nauthor: Muhammad Faisal (@faisalusuf)\ndate: 2023-01-27\nreferences:\n    - https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts\n    - https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-security-and-analysis-settings-for-your-organization\ntags:\n    - attack.initial-access\n    - attack.t1195.001\nlogsource:\n    product: github\n    service: audit\n    definition: 'Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming'\ndetection:\n    selection:\n        action:\n            - 'dependabot_alerts_new_repos.disable'\n            - 'dependabot_alerts.disable'\n            - 'dependabot_security_updates_new_repos.disable'\n            - 'dependabot_security_updates.disable'\n            - 'repository_vulnerability_alerts.disable'\n    condition: selection\nfalsepositives:\n    - Approved changes by the Organization owner. Please validate the 'actor' if authorized to make the changes.\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1195.001","id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","page":"techniques/enterprise/T1195.001/"}],"data_path":"data/detection-rules/34e1c7d4-0cd5-419d-9f1b-1dad3f61018d.json","kind":"sigma"}
