Automated Scanning of Jenkins/CI-CD Management Endpoints
Detects web requests targeting sensitive Jenkins/CI-CD administrative and build-triggering endpoints, such as /script, /manage, and /job/*/build. These paths are high-value targets for reconnaissance and automated exploitation efforts. This rule identifies potentially malicious activity by monitoring for access to these specific paths, which should be correlated with frequency and source data to differentiate automated scanning from authorized administrative or system activities.
Sigma

