Atlassian
Telemetry Evidence
These values show how indexed rules identify Atlassian telemetry.Kusto
atlassian_beacon_alerts_CL JiraAudit Panther
Atlassian.Audit atlassian Sigma
bitbucket
Detection Rules
Kusto #
- Jira - Global permission added source medium: 'Detects when global permission added.'
T1078 - Jira - New site admin user source high: 'Detects new site admin user.'
T1078 - Jira - New site admin user source high: 'Detects new site admin user.'
T1078 - Jira - New user created source medium: 'Detects when new user was created.'
T1078 - Jira - Permission scheme updated source medium: 'Detects when permission scheme was updated.'
T1531 - Jira - Project roles changed source medium: 'Detects when project roles were changed.'
T1531 - Jira - User removed from group source medium: 'Detects when a user was removed from group.'
T1531 - Jira - User removed from project source medium: 'Detects when a user was removed from project.'
T1531 - Jira - User's password changed multiple times source high: 'Detects when user's password was changed multiple times from different IP addresses.'
T1078 - Jira - Workflow scheme copied source medium: 'Detects when workflow scheme was copied.'
T1213
Panther #
- Admin Role Assigned source medium: Assigning an admin role manually could be a sign of privilege escalation
T1078 - Atlassian admin impersonated another user source high: Reports when an Atlassian user logs in (impersonates) another user.
- Brute Force By IP source informational: An actor user was denied login access more times than the configured threshold.
T1110 - Brute Force By User source informational: An actor user was denied login access more times than the configured threshold.
T1110 - GreyNoise V3 Malicious IP Activity source high: Detects when an IP address in any log event is classified as malicious or unknown by GreyNoise V3 internet scanner intelligence. Known business services and benign IPs are excluded.
T1595.001 - GTI/VirusTotal Threat Intelligence Indicator Match source high: Detects when an IP address, domain, or file hash in any log event matches a known malicious indicator from Google Threat Intelligence (GTI) / VirusTotal enrichment. Severity is elevated based on GTI's threat severity verdict and the number of vendors flagging the indicator as malicious.
T1595.001 - MFA Disabled source high: Detects when Multi-Factor Authentication (MFA) is disabled
T1556 - OTX Threat Intelligence Indicator Match source high: Detects when an IP address in any log event matches a known threat indicator from AlienVault OTX pulse intelligence. Severity is elevated when the pulse includes a named adversary or known malware families.
T1595.001 - Sign In from Rogue State source medium: Detects when an entity signs in from a nation associated with cyber attacks
T1078.004
Sigma #
- Bitbucket Audit Log Configuration Updated source medium: Detects changes to the bitbucket audit log configuration.
T1685 - Bitbucket Full Data Export Triggered source high: Detects when full data export is attempted.
T1213,T1213.003 - Bitbucket Global Permission Changed source medium: Detects global permissions change activity.
T1098 - Bitbucket Global Secret Scanning Rule Deleted source medium: Detects Bitbucket global secret scanning rule deletion activity.
T1685 - Bitbucket Global SSH Settings Changed source medium: Detects Bitbucket global SSH access configuration changes.
T1021,T1021.004,T1685 - Bitbucket Project Secret Scanning Allowlist Added source low: Detects when a secret scanning allowlist rule is added for projects.
T1685 - Bitbucket Secret Scanning Exempt Repository Added source high: Detects when a repository is exempted from secret scanning feature.
T1685 - Bitbucket Secret Scanning Rule Deleted source low: Detects when secret scanning rule is deleted for the project or repository.
T1685 - Bitbucket Unauthorized Access To A Resource source critical: Detects unauthorized access attempts to a resource.
T1586 - Bitbucket Unauthorized Full Data Export Triggered source critical: Detects when full data export is attempted an unauthorized user.
T1213,T1213.003,T1586
Show 4 more
- Bitbucket User Details Export Attempt Detected source medium: Detects user data export activity.
T1082,T1213,T1591,T1591.004 - Bitbucket User Login Failure source medium: Detects user authentication failure events. Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.
T1078,T1078.004,T1110 - Bitbucket User Login Failure Via SSH source medium: Detects SSH user login access failures. Please note that this rule can be noisy and is recommended to use with correlation based on "author.name" field.
T1021,T1021.004,T1110 - Bitbucket User Permissions Export Attempt source medium: Detects user permission data export attempt.
T1082,T1213,T1591,T1591.004
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Kusto #