Rule Info
Name
GitLab Token Access Via GLAB CLI - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens.
Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
Reference
Date
2026-06-08 00:00:00
Modified
None
Id
5a9c2e7f-1d4b-4f8a-e3c6-9b0d5f2a8c4e
Tags
attack.credential-access attack.t1528
Type
Nextron Sigma feed only (private)
