Tag
medium
advisory
GitHub Organizations 2FA Disabled
3 rules 3 TTPsThe disabling of two-factor authentication (2FA) in GitHub Organizations is detected through audit log monitoring, potentially indicating an attacker's attempt to weaken account security and facilitate unauthorized access.
github.com +3
github
2fa
security_controls
supply_chain
3r
3t
high
advisory
Detection of PowerShell Execution Policy Changes to Unrestricted or Bypass
2 rules 1 TTPDetection of modifications to the PowerShell execution policy to 'Unrestricted' or use of the 'Bypass' flag indicates a potential attempt to execute unsigned or malicious scripts, bypassing security controls.
PowerShell
execution_policy
bypass
security_controls
2r
1t