# Custom rule: catch git-upload-pack/git-receive-pack forking anything other # than git's own pack-objects binary. Added after the 2026-08-10/11 gitea # log-poisoning attack, which planted a malicious `uploadpack.packObjectsHook` # global git config entry - a documented git RCE primitive where upload-pack # forks an attacker-chosen executable instead of git-pack-objects on every # fetch/clone. This is the moment the backdoor actually fires, independent of # how the hook config got planted, so it's a strong last-line catch even if # git-hook-tamper.yaml's file-write detection is bypassed some other way. - list: git_pack_children items: [git-pack-objects, git, git-remote-https, git-remote-http] - rule: Unexpected child process of git pack service desc: > git-upload-pack or git-receive-pack spawned a process that isn't git's own pack-objects binary. Normal fetch/push never does this - it's the exact behavior of an abused uploadpack.packObjectsHook / pre-receive-style RCE. condition: > spawned_process and container.name = "gitea" and proc.pname in (git-upload-pack, git-receive-pack) and not proc.name in (git_pack_children) output: > git pack service spawned unexpected child process (user=%user.name command=%proc.cmdline parent=%proc.pname container=%container.name pid=%proc.pid) priority: CRITICAL tags: [git, execution, mitre_execution]