bitbucket_scan_external_internal

Explanation

This NDM is designed to detect scanning for Atlassian Bitbucket that is hitting the customer’s network from the Internet. Atlassian Bitbucket is a source code repository that has been subject to vulnerability disclosures in the past.

What to Look For

Scanning activity on the Internet is quite commonplace. On must networks, Atlassian Bitbucket should not be exposed to the Internet.

Related MITRE ATT&CK Categories

Reconnaissance: Active Scanning, Technique T1595 - Enterprise