Name:Circle CI Disable Security Step id:72cb9de9-e98b-4ac9-80b2-5331bba6ea97 version:9 date:None author:Patrick Bareiss, Splunk status:experimental type:Anomaly Description:The following analytic detects the disablement of security steps in a CircleCI pipeline. It leverages CircleCI logs, using field renaming, joining, and statistical analysis to identify instances where mandatory security steps are not executed. This activity is significant because disabling security steps can introduce vulnerabilities, unauthorized changes, or malicious code into the pipeline. If confirmed malicious, this could lead to potential attacks, data breaches, or compromised infrastructure. Investigate by reviewing job names, commit details, and user information associated with the disablement, and examine any relevant artifacts and concurrent processes. Data_source:
-CircleCI
search:`circleci`
| rename workflows.job_id AS job_id
| join job_id [
| search `circleci`
| stats values(name) as step_names count BY job_id job_name ]
how_to_implement:You must index CircleCI logs. known_false_positives:No false positives have been identified at this time. References: drilldown_searches:
: analytic_story:['Dev Sec Ops']
tests: name:'True Positive Test' attack_data: data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1554/circle_ci_disable_security_step/circle_ci_disable_security_step.json sourcetype: circleci source: circleci test_type:'experimental' description:'This test is a legacy experimental test and may not be accurate.' manual_test:None