GitLab
Telemetry Evidence
These values show how indexed rules identify GitLab telemetry.Kusto
GitLabAccess GitLabApp GitLabAudit SigninLogs Application = GitLab GitLab Panther
GitLab.Audit GitLab.Production gitlab
Detection Rules
Kusto #
- GitLab - Abnormal number of repositories deleted source medium: 'This hunting queries identify an unusual increase of repo deletion activities adversaries may want to disrupt availability or compromise integrity by deleting business data.'
T1485 - GitLab - Brute-force Attempts source medium: 'This query relies on GitLab Application Logs to get failed logins to highlight brute-force attempts from different IP addresses in a short space of time.'
T1110 - GitLab - External User Added to GitLab source medium: 'This queries GitLab Application logs to list external user accounts (i.e.: account not in allow-listed domains) which have been added to GitLab users.'
T1136 - GitLab - Local Auth - No MFA source medium: 'This query checks GitLab Audit Logs to see if a user authenticated without MFA. Ot might mean that MFA was disabled for the GitLab server or that an external authentication provider was bypassed. This rule focuses on 'admin' privileges but the parameter can be adapted to also include all users.'
T1110 - GitLab - Personal Access Tokens creation over time source medium: 'This queries GitLab Audit Logs for access tokens. Attacker can exfiltrate data from you GitLab repository after gaining access to it by generating or hijacking access tokens. This hunting queries allows you to track the personal access tokens creation for each of your repositories. The visualization allow you to quickly identify anomalies/excessive creation, to further investigate repo access & permissions.'
T1213 - GitLab - Repository visibility to Public source medium: 'This query leverages GitLab Audit Logs. A repository in GitLab changed visibility from Private or Internal to Public which could indicate compromise, error or misconfiguration leading to exposing the repository to the public.'
T1556 - GitLab - TI - Connection from Malicious IP source medium: 'This query correlates Threat Intelligence data from Microsoft Sentinel with GitLab NGINX Access Logs (available in GitLab CE as well) to identify access from potentially TI-flagged IPs.'
T1078 - GitLab - User Impersonation source medium: 'This queries GitLab Audit Logs for user impersonation. A malicious operator or a compromised admin account could leverage the impersonation feature of GitLab to change code or repository settings bypassing usual processes. This hunting queries allows you to track the audit actions done under impersonation.'
T1078
Panther #
- CVE-2023-7028 - GitLab Audit Password Reset Multiple Emails source high: Attackers are exploiting a Critical (CVSS 10.0) GitLab vulnerability in which user account password reset emails could be delivered to an unverified email address.
T1098,T1190,T1195 - CVE-2023-7028 - GitLab Production Password Reset Multiple Emails source high: Attackers are exploiting a Critical (CVSS 10.0) GitLab vulnerability in which user account password reset emails could be delivered to an unverified email address.
T1098,T1190,T1195
Product-Filtered Rules
These rules use generic transport telemetry with a product-specific filter for GitLab.Kusto #
T1110