CI/CD Pipeline Poisoning via External DNS Lookups from Build Agents T1195.001
This rule monitors build agent processes (e.g., Jenkins, Bamboo, Gradle, MSBuild) for suspicious DNS activity. It alerts when these processes resolve a high volume (3 or more) of unique external domains that are not associated with typical development, build, or dependency management platforms (e.g., Microsoft, Azure, GitHub, NPM, PyPI, Maven, Sonatype). This behavior may indicate an attempt by an adversary to reach command-and-control servers or exfiltrate data from a compromised build environment.
Splunk (SPL)

