Hayabusa medium test sigma
Github Self-Hosted Runner Execution
Detects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.
Detection Logic
{
"process_creation": {
"EventID": 1,
"Channel": "Microsoft-Windows-Sysmon/Operational"
},
"selection_worker_img": [
{
"Image
| endswith": "\\Runner.Worker.exe"
},
{
"OriginalFileName": "Runner.Worker.dll"
}
],
"selection_worker_cli": {
"CommandLine
| contains": "spawnclient"
},
"selection_listener_img": [
{
"Image
| endswith": "\\Runner.Listener.exe"
},
{
"OriginalFileName": "Runner.Listener.dll"
}
],
"selection_listener_cli": {
"CommandLine
| contains": [
"run",
"configure"
]
},
"condition": "process_creation and (all of selection_worker_* or all of selection_listener_*)"
} False Positives
- ⚠ Legitimate GitHub self-hosted runner installations on designated CI/CD infrastructure
- ⚠ Authorized runner deployments by DevOps/Platform teams following change management
- ⚠ Scheduled runner updates or reconfigurations on existing build agents
- ⚠ Self-hosted runners that follow expected/known naming patterns
- ⚠ Installation via expected/known configuration management tools (reflected mostly as parent process name)
Field Validations
Loading…
Comments (0)
Loading comments...