CI/CD workflow file tampered to enable auto-trigger/unattended publish
This rule detects modifications to GitHub Actions workflow configuration files (.yml or .yaml) located in the .github/workflows/ directory. Such modifications may indicate unauthorized tampering with CI/CD pipelines to facilitate persistent execution, credential theft, or supply chain attacks.
SentinelOne

