Rule Info
Name
GitHub Token Access Via GH CLI - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens.
Threat actors might access such tokens to gain unauthorized access to GitHub repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
Date
2026-06-08 00:00:00
Modified
None
Id
2a5c8f3e-9b1d-4e7a-c6f0-3d8b2e5a9c1f
Tags
attack.credential-access attack.t1528
Type
Nextron Sigma feed only (private)
