// MITRE ATT&CK

T1593.003 · Code Repositories

🎯 Reconnaissance PRE Sub-technique

Sub-technique of T1593 · Search Open Websites/Domains.

Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositories on various third-party websites such as GitHub, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web ap...

How to detect & mitigate it

Detecting Code Repositories starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.