046d52c902
* [New Rule] Execution via GitHub Runner with Audit Disabled via Environment Variables * [New Rule] Tampering with RUNNER_TRACKING_ID in GitHub Actions Runners * ++ * ++ * Update execution_via_github_runner_with_runner_tracking_id_tampering_via_env_vars.toml * Remove 'Use Case: Vulnerability' entry Removed 'Use Case: Vulnerability' from the list. * Add timestamp override to GitHub runner execution rules * Update rules/cross-platform/execution_via_github_runner_with_runner_tracking_id_tampering_via_env_vars.toml * Enhance guide for RUNNER_TRACKING_ID tampering Added detailed investigation guide for tampering with RUNNER_TRACKING_ID in GitHub Actions runners, including triage steps, false positive analysis, and remediation actions.