Rule Info
Name
GitLab Token Access Via GLAB CLI
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens.
Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
Reference
Date
2026-06-08 00:00:00
Modified
None
Id
8f3d1e5a-4c9b-4a2f-d7e0-2b6c8f4a1d9e
Tags
attack.credential-access attack.t1528
Type
Nextron Sigma feed only (private)
