[metadata] creation_date = "2023/08/29" integration = ["github"] maturity = "production" updated_date = "2024/05/21" [rule] author = ["Elastic"] description = """ This rule detects when a GitHub repository is deleted within your organization. Repositories are a critical component used within an organization to manage work, collaborate with others and release products to the public. Any delete action against a repository should be investigated to determine it's validity. Unauthorized deletion of organization repositories could cause irreversible loss of intellectual property and indicate compromise within your organization. """ from = "now-9m" index = ["logs-github.audit-*"] language = "eql" license = "Elastic License v2" name = "GitHub Repository Deleted" risk_score = 47 rule_id = "345889c4-23a8-4bc0-b7ca-756bd17ce83b" severity = "medium" tags = [ "Domain: Cloud", "Use Case: Threat Detection", "Use Case: UEBA", "Tactic: Impact", "Data Source: Github", ] timestamp_override = "event.ingested" type = "eql" query = ''' configuration where event.module == "github" and event.action == "repo.destroy" ''' [[rule.threat]] framework = "MITRE ATT&CK" [[rule.threat.technique]] id = "T1485" name = "Data Destruction" reference = "https://attack.mitre.org/techniques/T1485/" [rule.threat.tactic] id = "TA0040" name = "Impact" reference = "https://attack.mitre.org/tactics/TA0040/"