Git branch created with SHA-shaped name to spoof pinned commit
This rule detects the creation of Git branches or tags using names that match the 40-character or 64-character hexadecimal format of Git commit hashes. This technique, identified in the context of Plugin4Shell, is used to spoof pinned-commit references, potentially misleading automated systems or developers into using malicious code versions.
Microsoft Sentinel (KQL)

