CI/CD Pipeline Credential File Access by Unexpected Process
Detects unauthorized access or modification to common CI/CD credential files (.npmrc, .pypirc, .git-credentials, jenkins credentials.xml) and CI/CD configuration files (.github/workflows, .gitlab-ci.yml). The rule monitors both file system activities by non-standard processes and the execution of command-line tools that reference these sensitive files.
SentinelOne

