GitHub-business-advanced-security
4 operations, identified by action in the audit log.
| action | Description |
|---|---|
| business_advanced_security.disabled | GitHub Advanced Security was disabled for your enterprise. |
| business_advanced_security.disabled_for_new_repos | GitHub Advanced Security was disabled for new repositories in your enterprise. |
| business_advanced_security.disabled_for_new_user_namespace_repos | GitHub Advanced Security was disabled for new user namespace repositories in your enterprise. |
| business_advanced_security.user_namespace_repos_disabled | GitHub Advanced Security was disabled for user namespace repositories in your enterprise. |
business_advanced_security.disabled
#Description
GitHub Advanced Security was disabled for your enterprise.
Fields #
| Name | Description |
|---|---|
action | The audit-log action string (e.g. repo.create). |
actor | Login of the user (or app) that performed the action. |
actor_id | Numeric ID of the actor. |
user | Login of the user the action targeted, when applicable. |
org | Organization in which the action occurred. |
repo | Repository the action targeted (owner/name), when applicable. |
business | Enterprise account, when the org belongs to one. |
@timestamp | Time the event was recorded (epoch ms). |
created_at | Time the action occurred (epoch ms). |
operation_type | Operation class: create, modify, remove, access, transfer, authentication. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
action | eq | org.disable_two_factor_requirement | 1 rule | sigma, splunk |
Detection Rules #
View all rules referencing this event →Sigma #
business_advanced_security.disabled_for_new_repos
#Description
GitHub Advanced Security was disabled for new repositories in your enterprise.
Fields #
| Name | Description |
|---|---|
action | The audit-log action string (e.g. repo.create). |
actor | Login of the user (or app) that performed the action. |
actor_id | Numeric ID of the actor. |
user | Login of the user the action targeted, when applicable. |
org | Organization in which the action occurred. |
repo | Repository the action targeted (owner/name), when applicable. |
business | Enterprise account, when the org belongs to one. |
@timestamp | Time the event was recorded (epoch ms). |
created_at | Time the action occurred (epoch ms). |
operation_type | Operation class: create, modify, remove, access, transfer, authentication. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
action | eq | org.disable_two_factor_requirement | 1 rule | sigma, splunk |
Detection Rules #
View all rules referencing this event →Sigma #
business_advanced_security.disabled_for_new_user_namespace_repos
#Description
GitHub Advanced Security was disabled for new user namespace repositories in your enterprise.
Fields #
| Name | Description |
|---|---|
action | The audit-log action string (e.g. repo.create). |
actor | Login of the user (or app) that performed the action. |
actor_id | Numeric ID of the actor. |
user | Login of the user the action targeted, when applicable. |
org | Organization in which the action occurred. |
repo | Repository the action targeted (owner/name), when applicable. |
business | Enterprise account, when the org belongs to one. |
@timestamp | Time the event was recorded (epoch ms). |
created_at | Time the action occurred (epoch ms). |
operation_type | Operation class: create, modify, remove, access, transfer, authentication. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
action | eq | org.disable_two_factor_requirement | 1 rule | sigma, splunk |
Detection Rules #
View all rules referencing this event →Sigma #
business_advanced_security.user_namespace_repos_disabled
#Description
GitHub Advanced Security was disabled for user namespace repositories in your enterprise.
Fields #
| Name | Description |
|---|---|
action | The audit-log action string (e.g. repo.create). |
actor | Login of the user (or app) that performed the action. |
actor_id | Numeric ID of the actor. |
user | Login of the user the action targeted, when applicable. |
org | Organization in which the action occurred. |
repo | Repository the action targeted (owner/name), when applicable. |
business | Enterprise account, when the org belongs to one. |
@timestamp | Time the event was recorded (epoch ms). |
created_at | Time the action occurred (epoch ms). |
operation_type | Operation class: create, modify, remove, access, transfer, authentication. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
action | eq | org.disable_two_factor_requirement | 1 rule | sigma, splunk |
Detection Rules #
View all rules referencing this event →Sigma #