Business
| action | Description | Sample | Rule |
|---|---|---|---|
| business. | An enterprise owner was added to an enterprise. | N | N |
| business. | A billing manager was added to an enterprise. | N | N |
| business. | An enterprise prevented access to resources by users with the given two-factor method. | N | N |
| business. | An organization was added to an enterprise. | Y | N |
| business. | A support entitlement was added to a member of an enterprise. | N | N |
| business. | Enablement for Advanced Security features on new repositories has been locked for this enterprise. | N | N |
| business. | Enablement for Advanced Security features on new repositories has been unlocked for this enterprise. | N | N |
| business. | An enterprise owner created, updated, or removed a policy for GitHub Advanced Security. | N | N |
| business. | N | N | |
| business. | An export of the enterprise audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query. | N | N |
| business. | An export of the enterprise's Git events was created. | N | N |
| business. | An invitation for someone to be an owner of an enterprise was canceled. | N | N |
| business. | An invitation for someone to be an billing manager of an enterprise was canceled. | N | N |
| business. | The trial of GitHub Enterprise Cloud was canceled. | N | N |
| business. | The seats plan type was changed for an enterprise. | N | N |
| business. | An enterprise owner or site administrator cleared GitHub Actions policy settings for an enterprise. | N | N |
| business. | An enterprise owner cleared the base repository permission policy setting for an enterprise. | Y | N |
| business. | Cleared two-factor authentication restrictions for an enterprise. | N | N |
| business. | An enterprise owner cleared a restriction on repository creation in organizations in the enterprise. | Y | N |
| business. | The policy for Code Quality access was updated for an enterprise. | N | N |
| business. | The policy for Code Quality enablement was updated for an enterprise. | N | N |
| business. | The policy for Code scanning AI findings was updated for an enterprise. | N | N |
| business. | The policy for Code scanning autofix was updated for an enterprise. | N | N |
| business. | The policy for Code scanning autofix third party tools was updated for an enterprise. | N | N |
| business. | The policy for Code Security enablement was updated for an enterprise. | N | N |
| business. | Enablement for Code Security features on new repositories has been locked for this enterprise. | N | N |
| business. | Enablement for Code Security features on new repositories has been unlocked for this enterprise. | N | N |
| business. | Server statistics were exported for the enterprise. | N | N |
| business. | The enterprise account on a trial of GitHub Enterprise Cloud was upgraded to a paid enterprise account. | N | N |
| business. | An enterprise was created. | Y | N |
| business. | A trial of GitHub Enterprise Cloud began. | Y | N |
| business. | The enterprise was deleted. | N | Y |
| business. | A custom image was deleted for an enterprise. | N | N |
| business. | A custom image version was deleted for an enterprise. | N | N |
| business. | N | N | |
| business. | OIDC single sign-on was disabled for an enterprise. | N | Y |
| business. | SCIM provisioning for custom integrations that use the REST API was disabled for the enterprise. | N | N |
| business. | SAML single sign-on was disabled for an enterprise. | N | Y |
| business. | Display of IP addresses within audit log events for the enterprise was disabled. | N | N |
| business. | The requirement for members to have two-factor authentication enabled to access an enterprise was disabled. | N | Y |
| business. | OIDC single sign-on was enabled for an enterprise. | N | N |
| business. | SCIM provisioning for custom integrations that use the REST API was enabled for the enterprise. | N | N |
| business. | SAML single sign-on was enabled for an enterprise. | N | N |
| business. | Display of IP addresses within audit log events for the enterprise was enabled. | N | N |
| business. | The requirement for members to have two-factor authentication enabled to access an enterprise was enabled. | N | N |
| business. | A GitHub Enterprise Server license was downloaded. | N | N |
| business. | An enterprise has reached its enterprise teams limit. | N | N |
| business. | An enterprise is approaching its enterprise teams limit. | N | N |
| business. | The trial of GitHub Enterprise Cloud expired. | N | N |
| business. | GitHub Models billing was disabled for the business. | N | N |
| business. | GitHub Models billing was enabled for the business. | N | N |
| business. | License usage information was imported from a GitHub Enterprise Server instance to an enterprise account on GitHub.com. | N | N |
| business. | An invitation for someone to be an enterprise owner of an enterprise was sent. | N | Y |
| business. | An invitation for someone to be a billing manager of an enterprise was sent. | N | Y |
| business. | An invitation for someone to join an enterprise was sent. | N | N |
| business. | An enterprise owner unset a policy for whether members of an enterprise can update protected branches on repositories for individual organizations. Organization owners can choose whether to allow updating protected branches settings. | Y | N |
| business. | The ability for enterprise members to update branch protection rules was disabled. Only enterprise owners can update protected branches. | N | Y |
| business. | The ability for enterprise members to update branch protection rules was enabled. Enterprise owners and members can update protected branches. | Y | N |
| business. | An enterprise has reached its members limit. | N | N |
| business. | An enterprise has reached its organizations limit. | N | N |
| business. | An enterprise is approaching its organizations limit. | N | N |
| business. | The proxy security header was disabled for an enterprise. All users on the network can now access GitHub, unless blocked by other means. | N | N |
| business. | The proxy security header was enabled for an enterprise. When the header is provided in requests, only Enterprise Managed Users matching the header will be able to access GitHub. | N | N |
| business. | A user outside the enterprise tried to access GitHub while the proxy security header was enabled and provided in the request. | N | N |
| business. | An enterprise owner failed to sign into a enterprise with an external identity provider (IdP) using a recovery code. | N | N |
| business. | An enterprise owner successfully signed into an enterprise with an external identity provider (IdP) using a recovery code. | N | N |
| business. | An enterprise owner downloaded the enterprise's SSO recovery codes. | N | Y |
| business. | An enterprise owner generated the enterprise's SSO recovery codes. | N | Y |
| business. | An enterprise owner printed the enterprise's SSO recovery codes. | N | Y |
| business. | An enterprise owner viewed the enterprise's SSO recovery codes. | N | Y |
| business. | An enterprise owner was removed from an enterprise. | N | N |
| business. | A billing manager was removed from an enterprise. | N | N |
| business. | Removed a two-factor authentication method restriction for an enterprise. | N | N |
| business. | A member was removed from an enterprise. | N | N |
| business. | An organization was removed from an enterprise. | N | Y |
| business. | A support entitlement was removed from a member of an enterprise. | N | N |
| business. | The slug for the enterprise URL was renamed. | N | N |
| business. | The deleted enterprise was restored. | N | N |
| business. | The external identity for a member in an enterprise was revoked. | N | N |
| business. | The SAML single sign-on session for a member in an enterprise was revoked. | N | N |
| business. | Enablement for Secret Protection features on new repositories has been locked for this enterprise. | N | N |
| business. | Enablement for Secret Protection features on new repositories has been unlocked for this enterprise. | N | N |
| business. | N | N | |
| business. | A CSV export was requested on the "CodeQL pull request alerts" page. | N | N |
| business. | A CSV export was requested on the "Coverage" page. | N | N |
| business. | A CSV export was requested on the "Overview Dashboard" page. | N | N |
| business. | A CSV export was requested on the "Risk" page. | N | N |
| business. | The cache retention policy for GitHub Actions was set for an enterprise. | N | N |
| business. | The cache storage policy for GitHub Actions was set for an enterprise. | N | N |
| business. | The policy for requiring approvals for workflows from public forks was changed for an enterprise. | N | N |
| business. | The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an enterprise. | N | N |
| business. | The retention period for GitHub Actions artifacts and logs was changed for an enterprise. | N | N |
| business. | The default permissions granted to the GITHUB_TOKEN when running workflows were changed for an enterprise. | Y | N |
| business. | The policy for fork pull request workflows was changed for an enterprise. | N | N |
| business. | The policy for allowing GitHub Actions to create and approve pull requests was changed for an enterprise. | Y | N |
| business. | A SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your enterprise. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports. | N | N |
| business. | A trial email verification attempt failed for a GitHub Enterprise Cloud trial. | N | N |
| business. | A trial email verification resend was requested for a GitHub Enterprise Cloud trial. | Y | N |
| business. | A trial email verification was sent for a GitHub Enterprise Cloud trial. | Y | N |
| business. | The trial email was successfully verified for a GitHub Enterprise Cloud trial. | Y | N |
| business. | An enterprise owner or site administrator updated GitHub Actions policy settings for an enterprise. | N | N |
| business. | The base repository permission setting was updated for all organizations in an enterprise. | Y | N |
| business. | N | N | |
| business. | The repository creation setting was updated for an enterprise. | Y | N |
| business. | The policy setting for enterprise members inviting outside collaborators to repositories was updated. | Y | N |
| business. | N | N | |
| business. | The SAML single sign-on provider settings for an enterprise were updated. | N | Y |
| business. | The policy for removing user accounts when removing the last organization membership was updated. | N | N |
| business. | The organization was upgraded to an enterprise account. | N | N |
business.add_admin
#Description
An enterprise owner was added to an enterprise.
Documented on GitHub's enterprise audit log reference.
business.add_billing_manager
#Description
A billing manager was added to an enterprise.
Documented on GitHub's enterprise audit log reference.
business.add_disallowed_two_factor_method
#Description
An enterprise prevented access to resources by users with the given two-factor method.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.add_organization
#Description
An organization was added to an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783902059941,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDU=",
"action": "business.add_organization",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902059941,
"name": "example-business-2",
"operation_type": "create",
"org": "example-org",
"org_id": 9000004,
"organization_upgrade": false,
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.add_support_entitlee
#Description
A support entitlement was added to a member of an enterprise.
Documented on GitHub's enterprise audit log reference.
business.advanced_security_metered_usage_lock
#Description
Enablement for Advanced Security features on new repositories has been locked for this enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.advanced_security_metered_usage_unlock
#Description
Enablement for Advanced Security features on new repositories has been unlocked for this enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.advanced_security_policy_update
#Description
An enterprise owner created, updated, or removed a policy for GitHub Advanced Security.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.advanced_security_repo_admin_enablement_policy_update
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.audit_log_export
#Description
An export of the enterprise audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.audit_log_git_event_export
#Description
An export of the enterprise's Git events was created.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.cancel_admin_invitation
#Description
An invitation for someone to be an owner of an enterprise was canceled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.cancel_billing_manager_invitation
#Description
An invitation for someone to be an billing manager of an enterprise was canceled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.cancel_trial
#Description
The trial of GitHub Enterprise Cloud was canceled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.change_seats_plan_type
#Description
The seats plan type was changed for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.clear_actions_settings
#Description
An enterprise owner or site administrator cleared GitHub Actions policy settings for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.clear_default_repository_permission
#Description
An enterprise owner cleared the base repository permission policy setting for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783955163543,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDM=",
"action": "business.clear_default_repository_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783955163543,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"name": "example-business-2",
"operation_type": "modify",
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "94CE:3FE560:EE07A77:F2C4D48:6A54FEDB",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
References #
business.clear_disallowed_two_factor_methods
#Description
Cleared two-factor authentication restrictions for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.clear_members_can_create_repos
#Description
An enterprise owner cleared a restriction on repository creation in organizations in the enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783955164200,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDE=",
"action": "business.clear_members_can_create_repos",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783955164200,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"name": "example-business-2",
"operation_type": "modify",
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "94CE:3FE560:EE07E27:F2C50EF:6A54FEDB",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2",
"visibility": null
}
References #
business.code_quality_access_policy_update
#Description
The policy for Code Quality access was updated for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.code_quality_enablement_policy_update
#Description
The policy for Code Quality enablement was updated for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.code_scanning_ai_findings_policy_update
#Description
The policy for Code scanning AI findings was updated for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.code_scanning_autofix_policy_update
#Description
The policy for Code scanning autofix was updated for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.code_scanning_autofix_third_party_tools_policy_update
#Description
The policy for Code scanning autofix third party tools was updated for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.code_security_enablement_policy_update
#Description
The policy for Code Security enablement was updated for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.code_security_metered_usage_lock
#Description
Enablement for Code Security features on new repositories has been locked for this enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.code_security_metered_usage_unlock
#Description
Enablement for Code Security features on new repositories has been unlocked for this enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.connect_usage_metrics_export
#Description
Server statistics were exported for the enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.convert_trial
#Description
The enterprise account on a trial of GitHub Enterprise Cloud was upgraded to a paid enterprise account.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.create
#Description
An enterprise was created.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783902030764,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTM=",
"action": "business.create",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902030764,
"name": "example-business-2",
"operation_type": "create",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.create_trial
#Description
A trial of GitHub Enterprise Cloud began.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783902030990,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTA=",
"action": "business.create_trial",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902030990,
"name": "example-business-2",
"operation_type": "create",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.delete
#Description
The enterprise was deleted.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
T1485
business.delete_custom_image
#Description
A custom image was deleted for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.delete_custom_image_version
#Description
A custom image version was deleted for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.dependabot_alerts_repo_admin_enablement_policy_update
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.disable_oidc
#Description
OIDC single sign-on was disabled for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
T1562↳ also matches business.disable_saml, business.update_saml_provider_settings Panther #
T1562↳ also matches business.disable_saml, business.disable_two_factor_requirement, business.members_can_update_protected_branches.disable
business.disable_open_scim
#Description
SCIM provisioning for custom integrations that use the REST API was disabled for the enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.disable_saml
#Description
SAML single sign-on was disabled for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
T1562↳ also matches business.disable_oidc, business.update_saml_provider_settings Panther #
T1562↳ also matches business.disable_oidc, business.disable_two_factor_requirement, business.members_can_update_protected_branches.disable
business.disable_source_ip_disclosure
#Description
Display of IP addresses within audit log events for the enterprise was disabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.disable_two_factor_requirement
#Description
The requirement for members to have two-factor authentication enabled to access an enterprise was disabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Splunk #
T1195, T1685YARA-L #
T1562Panther #
T1562↳ also matches business.disable_oidc, business.disable_saml, business.members_can_update_protected_branches.disable
business.enable_oidc
#Description
OIDC single sign-on was enabled for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.enable_open_scim
#Description
SCIM provisioning for custom integrations that use the REST API was enabled for the enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.enable_saml
#Description
SAML single sign-on was enabled for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.enable_source_ip_disclosure
#Description
Display of IP addresses within audit log events for the enterprise was enabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.enable_two_factor_requirement
#Description
The requirement for members to have two-factor authentication enabled to access an enterprise was enabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.enterprise_server_license_download
#Description
A GitHub Enterprise Server license was downloaded.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.enterprise_teams_limit_reached
#Description
An enterprise has reached its enterprise teams limit.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.enterprise_teams_limit_warning
#Description
An enterprise is approaching its enterprise teams limit.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.expire_trial
#Description
The trial of GitHub Enterprise Cloud expired.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.github_models_billing_disabled
#Description
GitHub Models billing was disabled for the business.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.github_models_billing_enabled
#Description
GitHub Models billing was enabled for the business.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.import_license_usage
#Description
License usage information was imported from a GitHub Enterprise Server instance to an enterprise account on GitHub.com.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.invite_admin
#Description
An invitation for someone to be an enterprise owner of an enterprise was sent.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
business.invite_billing_manager
#Description
An invitation for someone to be a billing manager of an enterprise was sent.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
business.invite_unaffiliated_member
#Description
An invitation for someone to join an enterprise was sent.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.members_can_update_protected_branches.clear
#Description
An enterprise owner unset a policy for whether members of an enterprise can update protected branches on repositories for individual organizations. Organization owners can choose whether to allow updating protected branches settings.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783955167529,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMzA=",
"action": "business.members_can_update_protected_branches.clear",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783955167529,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"name": "example-business-2",
"operation_type": "modify",
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "94CE:3FE560:EE0907E:F2C63B8:6A54FEDF",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user": "user",
"user_agent": "python-requests/2.34.2",
"user_id": 9000002
}
References #
business.members_can_update_protected_branches.disable
#Description
The ability for enterprise members to update branch protection rules was disabled. Only enterprise owners can update protected branches.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1562↳ also matches business.disable_oidc, business.disable_saml, business.disable_two_factor_requirement
business.members_can_update_protected_branches.enable
#Description
The ability for enterprise members to update branch protection rules was enabled. Enterprise owners and members can update protected branches.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783955167237,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMzE=",
"action": "business.members_can_update_protected_branches.enable",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783955167237,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"name": "example-business-2",
"operation_type": "modify",
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "94CE:3FE560:EE08E95:F2C61DD:6A54FEDF",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user": "user",
"user_agent": "python-requests/2.34.2",
"user_id": 9000002
}
References #
business.members_limit_reached
#Description
An enterprise has reached its members limit.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.organizations_limit_reached
#Description
An enterprise has reached its organizations limit.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.organizations_limit_warning
#Description
An enterprise is approaching its organizations limit.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.proxy_security_header_disabled
#Description
The proxy security header was disabled for an enterprise. All users on the network can now access GitHub, unless blocked by other means.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.proxy_security_header_enabled
#Description
The proxy security header was enabled for an enterprise. When the header is provided in requests, only Enterprise Managed Users matching the header will be able to access GitHub.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.proxy_security_header_unsatisfied
#Description
A user outside the enterprise tried to access GitHub while the proxy security header was enabled and provided in the request.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.recovery_code_failed
#Description
An enterprise owner failed to sign into a enterprise with an external identity provider (IdP) using a recovery code.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.recovery_code_used
#Description
An enterprise owner successfully signed into an enterprise with an external identity provider (IdP) using a recovery code.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.recovery_codes_downloaded
#Description
An enterprise owner downloaded the enterprise's SSO recovery codes.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
business.recovery_codes_generated
#Description
An enterprise owner generated the enterprise's SSO recovery codes.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
business.recovery_codes_printed
#Description
An enterprise owner printed the enterprise's SSO recovery codes.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
business.recovery_codes_viewed
#Description
An enterprise owner viewed the enterprise's SSO recovery codes.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
business.remove_admin
#Description
An enterprise owner was removed from an enterprise.
Documented on GitHub's enterprise audit log reference.
business.remove_billing_manager
#Description
A billing manager was removed from an enterprise.
Documented on GitHub's enterprise audit log reference.
business.remove_disallowed_two_factor_method
#Description
Removed a two-factor authentication method restriction for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.remove_member
#Description
A member was removed from an enterprise.
Documented on GitHub's enterprise audit log reference.
business.remove_organization
#Description
An organization was removed from an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Splunk #
T1195, T1485YARA-L #
T1485
business.remove_support_entitlee
#Description
A support entitlement was removed from a member of an enterprise.
Documented on GitHub's enterprise audit log reference.
business.rename_slug
#Description
The slug for the enterprise URL was renamed.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.restore
#Description
The deleted enterprise was restored.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.revoke_external_identity
#Description
The external identity for a member in an enterprise was revoked.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.revoke_sso_session
#Description
The SAML single sign-on session for a member in an enterprise was revoked.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.secret_protection_metered_usage_lock
#Description
Enablement for Secret Protection features on new repositories has been locked for this enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.secret_protection_metered_usage_unlock
#Description
Enablement for Secret Protection features on new repositories has been unlocked for this enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.secret_scanning_repo_admin_settings_policy_update
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.security_center_export_code_scanning_metrics
#Description
A CSV export was requested on the "CodeQL pull request alerts" page.
Documented on GitHub's enterprise audit log reference.
business.security_center_export_coverage
#Description
A CSV export was requested on the "Coverage" page.
Documented on GitHub's enterprise audit log reference.
business.security_center_export_overview_dashboard
#Description
A CSV export was requested on the "Overview Dashboard" page.
Documented on GitHub's enterprise audit log reference.
business.security_center_export_risk
#Description
A CSV export was requested on the "Risk" page.
Documented on GitHub's enterprise audit log reference.
business.set_actions_cache_retention_policy
#Description
The cache retention policy for GitHub Actions was set for an enterprise.
Documented on GitHub's enterprise audit log reference.
business.set_actions_cache_storage_policy
#Description
The cache storage policy for GitHub Actions was set for an enterprise.
Documented on GitHub's enterprise audit log reference.
business.set_actions_fork_pr_approvals_policy
#Description
The policy for requiring approvals for workflows from public forks was changed for an enterprise.
Documented on GitHub's enterprise audit log reference.
business.set_actions_private_fork_pr_approvals_policy
#Description
The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an enterprise.
Documented on GitHub's enterprise audit log reference.
business.set_actions_retention_limit
#Description
The retention period for GitHub Actions artifacts and logs was changed for an enterprise.
Documented on GitHub's enterprise audit log reference.
business.set_default_workflow_permissions
#Description
The default permissions granted to the GITHUB_TOKEN when running workflows were changed for an enterprise.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"@timestamp": 1783902030910,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTE=",
"action": "business.set_default_workflow_permissions",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902030910,
"name": "example-business-2",
"operation_type": "modify",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.set_fork_pr_workflows_policy
#Description
The policy for fork pull request workflows was changed for an enterprise.
Documented on GitHub's enterprise audit log reference.
business.set_workflow_permission_can_approve_pr
#Description
The policy for allowing GitHub Actions to create and approve pull requests was changed for an enterprise.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"@timestamp": 1783902030884,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTI=",
"action": "business.set_workflow_permission_can_approve_pr",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902030884,
"name": "example-business-2",
"operation_type": "modify",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.sso_response
#Description
A SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your enterprise. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.trial_email_verification_failed
#Description
A trial email verification attempt failed for a GitHub Enterprise Cloud trial.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.trial_email_verification_requested
#Description
A trial email verification resend was requested for a GitHub Enterprise Cloud trial.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783902031677,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDk=",
"action": "business.trial_email_verification_requested",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902031677,
"name": "example-business-2",
"operation_type": "create",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.trial_email_verification_sent
#Description
A trial email verification was sent for a GitHub Enterprise Cloud trial.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783902031686,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDg=",
"action": "business.trial_email_verification_sent",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902031686,
"name": "example-business-2",
"operation_type": "create",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.trial_email_verified
#Description
The trial email was successfully verified for a GitHub Enterprise Cloud trial.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783902041198,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDc=",
"action": "business.trial_email_verified",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902041198,
"name": "example-business-2",
"operation_type": "modify",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B20635:7F48F01:6A542F4F",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
References #
business.update_actions_settings
#Description
An enterprise owner or site administrator updated GitHub Actions policy settings for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.update_default_repository_permission
#Description
The base repository permission setting was updated for all organizations in an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783955163225,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDQ=",
"action": "business.update_default_repository_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783955163225,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"name": "example-business-2",
"old_permission": "no_policy",
"operation_type": "modify",
"permission": "read",
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "94CE:3FE560:EE07847:F2C4B40:6A54FEDA",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
References #
business.update_emu_repo_self_hosted_runners_policy
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.update_member_repository_creation_permission
#Description
The repository creation setting was updated for an enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783955163886,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDI=",
"action": "business.update_member_repository_creation_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783955163886,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"name": "example-business-2",
"operation_type": "modify",
"permission": true,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "94CE:3FE560:EE07C0E:F2C4ECD:6A54FEDB",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2",
"visibility": "none"
}
References #
business.update_member_repository_invitation_permission
#Description
The policy setting for enterprise members inviting outside collaborators to repositories was updated.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.Example Audit Log Entry #
{
"@timestamp": 1783955166130,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMzQ=",
"action": "business.update_member_repository_invitation_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783955166130,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"name": "example-business-2",
"operation_type": "modify",
"permission": true,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "94CE:3FE560:EE088E5:F2C5C00:6A54FEDD",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
References #
business.update_repo_self_hosted_runners_policy
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.update_saml_provider_settings
#Description
The SAML single sign-on provider settings for an enterprise were updated.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
T1562↳ also matches business.disable_oidc, business.disable_saml
business.update_unaffiliated_users_policy
#Description
The policy for removing user accounts when removing the last organization membership was updated.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business.upgrade_from_organization
#Description
The organization was upgraded to an enterprise account.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.