logo

The source of everything

ID: 2e9f9e2e-ccb6-5060-b4fc-6dc84272ff67

STIX ID: report--2e9f9e2e-ccb6-5060-b4fc-6dc84272ff67

Feed Name: Group-IB Blog

Date Published: 2021-01-26

Date Updated: 2026-04-27

...
...

The article explains how attackers can abuse misconfigured CI/CD systems to access and exfiltrate source code, and provides a structured DFIR playbook that uses GitLab CE and Jenkins CI logs to reconstruct initial access, credential abuse, persistence, execution, collection, and exfiltration. It enumerates key evidence sources (e.g., GitLab production_json, application_json, api_json, and Nginx logs; Jenkins access logs, job logs, config and backup files), shows example log patterns for logins, failed logins, user and token creation, repository cloning, job starts, workspace access, and artifact downloads, highlights GitLab’s superior logging granularity versus Jenkins’ gaps, and concludes with SOC-oriented recommendations for monitoring, least privilege, secrets management, password policies, log forwarding to SIEM, and patch/secure configuration to prevent and investigate source code compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.