GitHub-business-advanced-security

4 operations, identified by action in the audit log.

actionDescription
business_advanced_security.disabledGitHub Advanced Security was disabled for your enterprise.
business_advanced_security.disabled_for_new_reposGitHub Advanced Security was disabled for new repositories in your enterprise.
business_advanced_security.disabled_for_new_user_namespace_reposGitHub Advanced Security was disabled for new user namespace repositories in your enterprise.
business_advanced_security.user_namespace_repos_disabledGitHub Advanced Security was disabled for user namespace repositories in your enterprise.

business_advanced_security.disabled

#
Category
GitHub-business-advanced-security

Description

GitHub Advanced Security was disabled for your enterprise.

Fields #

NameDescription
actionThe audit-log action string (e.g. repo.create).
actorLogin of the user (or app) that performed the action.
actor_idNumeric ID of the actor.
userLogin of the user the action targeted, when applicable.
orgOrganization in which the action occurred.
repoRepository the action targeted (owner/name), when applicable.
businessEnterprise account, when the org belongs to one.
@timestampTime the event was recorded (epoch ms).
created_atTime the action occurred (epoch ms).
operation_typeOperation class: create, modify, remove, access, transfer, authentication.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
actioneqorg.disable_two_factor_requirement1 rulesigma, splunk

Detection Rules #

View all rules referencing this event →

Sigma #

business_advanced_security.disabled_for_new_repos

#
Category
GitHub-business-advanced-security

Description

GitHub Advanced Security was disabled for new repositories in your enterprise.

Fields #

NameDescription
actionThe audit-log action string (e.g. repo.create).
actorLogin of the user (or app) that performed the action.
actor_idNumeric ID of the actor.
userLogin of the user the action targeted, when applicable.
orgOrganization in which the action occurred.
repoRepository the action targeted (owner/name), when applicable.
businessEnterprise account, when the org belongs to one.
@timestampTime the event was recorded (epoch ms).
created_atTime the action occurred (epoch ms).
operation_typeOperation class: create, modify, remove, access, transfer, authentication.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
actioneqorg.disable_two_factor_requirement1 rulesigma, splunk

Detection Rules #

View all rules referencing this event →

Sigma #

business_advanced_security.disabled_for_new_user_namespace_repos

#
Category
GitHub-business-advanced-security

Description

GitHub Advanced Security was disabled for new user namespace repositories in your enterprise.

Fields #

NameDescription
actionThe audit-log action string (e.g. repo.create).
actorLogin of the user (or app) that performed the action.
actor_idNumeric ID of the actor.
userLogin of the user the action targeted, when applicable.
orgOrganization in which the action occurred.
repoRepository the action targeted (owner/name), when applicable.
businessEnterprise account, when the org belongs to one.
@timestampTime the event was recorded (epoch ms).
created_atTime the action occurred (epoch ms).
operation_typeOperation class: create, modify, remove, access, transfer, authentication.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
actioneqorg.disable_two_factor_requirement1 rulesigma, splunk

Detection Rules #

View all rules referencing this event →

Sigma #

business_advanced_security.user_namespace_repos_disabled

#
Category
GitHub-business-advanced-security

Description

GitHub Advanced Security was disabled for user namespace repositories in your enterprise.

Fields #

NameDescription
actionThe audit-log action string (e.g. repo.create).
actorLogin of the user (or app) that performed the action.
actor_idNumeric ID of the actor.
userLogin of the user the action targeted, when applicable.
orgOrganization in which the action occurred.
repoRepository the action targeted (owner/name), when applicable.
businessEnterprise account, when the org belongs to one.
@timestampTime the event was recorded (epoch ms).
created_atTime the action occurred (epoch ms).
operation_typeOperation class: create, modify, remove, access, transfer, authentication.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
actioneqorg.disable_two_factor_requirement1 rulesigma, splunk

Detection Rules #

View all rules referencing this event →

Sigma #