Git checkout hijack via branch named as pinned 40-hex commit SHA
Detects Git checkout operations involving specific SHA hash arguments that occur in conjunction with potential ambiguous refname errors, or are initiated by processes commonly used for AI-assisted coding (e.g., Copilot, Claude). This rule monitors for potentially malicious source code repository manipulation or automated branch hijacking attempts, often seen in supply chain or development environment attacks.
Microsoft Sentinel (KQL)

