elastic
medium
eql
Execution via GitHub Actions Runner
This rule detects potentially dangerous commands spawned by the GitHub Actions Runner.Worker process or by shell
interpreters launched via a runner entrypoint script on self-hosted runner machines. Adversaries who gain the ability
to modify or trigger workflows in a linked GitHub repository can execute arbitrary commands on the runner host. This
behavior may indicate malicious or unexpected workflow activity, including code execution, reconnaissance, credential
harvesting, or network exfiltratio