Anomalous fork

ID

fork_anomalous

Severity

high

Resource

Repository

Description

Detects whether a fork has some anomalous clues.

Several relevant factors are evaluated for clues to determine if a fork is anomalous. These are some of them:

  • The user account creation is too recent.

  • The user doesn’t have any activity.

  • The user doesn’t have any recent activity.

Impact

A repository fork from an unusual user may indicate the start of the preparation stage for subsequent malicious actions, and it could increase the risk of security breaches, intellectual property theft, compliance violations and reputation damage.

Supported Technologies

This detector is supported by the following sensors:

GitHub Actions   GitHub Sensor

Bitbucket Sensor   Bitbucket Sensor