Classify pipeline incident observations into adversary tactic buckets.
Sort each CI/CD observation into the adversary tactic bucket it most directly suggests. Discovery Credential Access Persistence Command and Control or Exfiltration Runner lists all private repositories available to its token Job prints masked and unmasked environment variable names Workflow attempts to read cloud access keys from CI variables Unknown process calls the cloud STS API to validate a role token A new third-party action is added to a trusted reusable workflow Package publish token is added to an unfamiliar runner group Runner opens repeated HTTPS connections to an unknown external domain Build artifacts are uploaded to a storage bucket…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in