Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0263 — Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms
DET0263

Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0732 Analytic 0732
SaaS

Anomalous or bulk download activity from private or restricted repositories by non-developer or privileged accounts, often preceded by unusual login behavior (e.g., unfamiliar geo, OAuth token use, elevated API rate).

saas:github repo.download, repo.clone, oauth.authorize, repo.getContent saas:github Login from unusual IP, device fingerprint, or location; access token creation from new client saas:github Bulk access to multiple files or large volume of repo requests within short time window
[TimeWindow] Threshold for file access volume over short duration (e.g., 10+ repos accessed in <5 min)
[UserContext] Role or permission profile expected to interact with repositories (e.g., developers vs. admins)
[GeoAnomalyThreshold] Distance or variance allowed before a login is flagged as anomalous
[RepoSensitivityTag] Whether a repository is labeled sensitive or restricted

Detected Techniques

1

Details

MITRE ID
DET0263
STIX ID
x-mitre-detection-strategy--574968c5-ca49-4005-958f-c3ea5a78cfbc
Analytics
1
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.