Detection of Bypassed Mandatory Security Jobs in CircleCI Pipelines
Detection of unauthorized omission of mandatory security jobs within CircleCI workflows which could indicate an attacker attempting to bypass CI/CD pipeline integrity checks.
This threat brief addresses the risk of unauthorized modifications to CI/CD pipeline configurations in CircleCI, specifically where mandatory security jobs are omitted or disabled. Attackers targeting the software supply chain may attempt to alter pipeline workflows to bypass automated security testing, such as SAST, DAST, or dependency scanning. By disabling these mandatory jobs, malicious code can be introduced into the development lifecycle without triggering alerts or automated blocks. This analytic identifies such anomalies by monitoring CircleCI logs and validating that required security tasks are executed within every workflow. Detecting this activity is critical for maintaining pipeline integrity and preventing the deployment of compromised artifacts.
Attack Chain
- An attacker gains access to the version control system or the CI/CD configuration files (e.g., .circleci/config.yml) associated with the project.
- The attacker modifies the workflow configuration to exclude mandatory security or quality assurance jobs.
- The attacker pushes the malicious or modified configuration file to the repository.
- CircleCI detects the new configuration and triggers the CI/CD pipeline.
- The pipeline executes the modified workflow, skipping the required security scanning tasks.
- The pipeline completes successfully without performing the necessary security validations.
- Malicious code is processed through the pipeline, potentially leading to unauthorized execution or compromised software delivery.
Impact
Successful bypass of security checks in a CI/CD pipeline can lead to the introduction of vulnerabilities or malicious payloads into production environments. This compromise threatens the integrity of the organization's software supply chain, potentially leading to data breaches, system downtime, and severe reputational damage.
Recommendation
Detection engineering teams should monitor CircleCI logs for workflow execution anomalies. Implement the provided logic to track mandatory security jobs against reported execution logs to identify unauthorized workflow modifications.
- Implement visibility into CircleCI pipeline logs to monitor job execution status.
- Review and maintain a strict list of mandatory security jobs that must run in every project workflow.
- Investigate any pipeline workflow where a mandatory security job is skipped or absent.
- Enforce code signing or branch protection rules in the source control management system to prevent unauthorized modifications to pipeline configuration files.
Immediate actions
Deploy CircleCI log monitoring and configure the mandatory job lookup table.
Threat Hunt
Identify all workflows currently running in CircleCI that lack recent security scanning job executions.
Data: CircleCI job execution history
Mitigations
Enable branch protection and require peer review for all changes to .circleci/config.yml files.
T1554
Detection coverage 1
Detect Omission of Mandatory Security Jobs in CircleCI
mediumDetects instances where mandatory security jobs are missing from a CircleCI workflow execution, indicating a potential bypass of security scanning.
Detection queries are available on the platform. Get full rules →