GitLab - External User Added to GitLab

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This queries GitLab Application logs to list external user accounts (i.e.: account not in allow-listed domains) which have been added to GitLab users.

Attribute Value
Type Analytic Rule
Solution GitLab
ID c1544d8f-cbbd-4e35-8d32-5b9312279833
Severity Medium
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1136
Required Connectors SyslogAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
Syslog Facility == "local7"
ProcessName == "GitLab-Audit-Logs"
?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to GitLab