Fan-out repo pushes from one developer identity indicating stolen credential abu
Detects a single developer identity performing a high volume of git push or clone operations across a large number of distinct repositories within a short timeframe. This behavior is indicative of a compromised developer account being used to programmatically inject code into multiple repositories, potentially for a supply chain attack or mass payload propagation.
Microsoft Sentinel (KQL)

