{"id":"eaa9ac35-1730-441f-9587-25767bde99d7","title":"Github Outside Collaborator Detected","description":"Detects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an owner removes an outside collaborator from an organization or when two-factor authentication is required in an organization and an outside collaborator does not use 2FA or disables 2FA.\n","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2023-01-20","modified":"","tags":["attack.privilege-escalation","attack.persistence","attack.collection","attack.t1098.001","attack.t1098.003","attack.t1213.003"],"technique_ids":["T1098.001","T1098.003","T1213.003"],"logsource":{"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"},"falsepositives":["Validate the actor if permitted to access the repo.","Validate the Multifactor Authentication changes."],"references":["https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#audit-log-actions","https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization"],"source_path":"rules/application/github/audit/github_outside_collaborator_detected.yml","source_sha256":"84feb937cafe75cbcf92931d0ef17cb8735653b99a201f60d99acffc200cab78","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/github/audit/github_outside_collaborator_detected.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Github Outside Collaborator Detected\nid: eaa9ac35-1730-441f-9587-25767bde99d7\nstatus: test\ndescription: |\n    Detects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an owner removes an outside collaborator from an organization or when two-factor authentication is required in an organization and an outside collaborator does not use 2FA or disables 2FA.\nauthor: Muhammad Faisal (@faisalusuf)\ndate: 2023-01-20\nreferences:\n    - https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#audit-log-actions\n    - https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.collection\n    - attack.t1098.001\n    - attack.t1098.003\n    - attack.t1213.003\nlogsource:\n    product: github\n    service: audit\n    definition: 'Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming'\ndetection:\n    selection:\n        action:\n            - 'org.remove_outside_collaborator'\n            - 'project.update_user_permission'\n    condition: selection\nfalsepositives:\n    - Validate the actor if permitted to access the repo.\n    - Validate the Multifactor Authentication changes.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1098.001","id":"T1098.001","name":"Additional Cloud Credentials","page":"techniques/enterprise/T1098.001/"},{"key":"enterprise/T1098.003","id":"T1098.003","name":"Additional Cloud Roles","page":"techniques/enterprise/T1098.003/"},{"key":"enterprise/T1213.003","id":"T1213.003","name":"Code Repositories","page":"techniques/enterprise/T1213.003/"}],"data_path":"data/detection-rules/eaa9ac35-1730-441f-9587-25767bde99d7.json","kind":"sigma"}
