Business

actionDescriptionSampleRule
business.add_adminAn enterprise owner was added to an enterprise.NN
business.add_billing_managerA billing manager was added to an enterprise.NN
business.add_disallowed_two_factor_methodAn enterprise prevented access to resources by users with the given two-factor method.NN
business.add_organizationAn organization was added to an enterprise.YN
business.add_support_entitleeA support entitlement was added to a member of an enterprise.NN
business.advanced_security_metered_usage_lockEnablement for Advanced Security features on new repositories has been locked for this enterprise.NN
business.advanced_security_metered_usage_unlockEnablement for Advanced Security features on new repositories has been unlocked for this enterprise.NN
business.advanced_security_policy_updateAn enterprise owner created, updated, or removed a policy for GitHub Advanced Security.NN
business.advanced_security_repo_admin_enablement_policy_updateNN
business.audit_log_exportAn export of the enterprise audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query.NN
business.audit_log_git_event_exportAn export of the enterprise's Git events was created.NN
business.cancel_admin_invitationAn invitation for someone to be an owner of an enterprise was canceled.NN
business.cancel_billing_manager_invitationAn invitation for someone to be an billing manager of an enterprise was canceled.NN
business.cancel_trialThe trial of GitHub Enterprise Cloud was canceled.NN
business.change_seats_plan_typeThe seats plan type was changed for an enterprise.NN
business.clear_actions_settingsAn enterprise owner or site administrator cleared GitHub Actions policy settings for an enterprise.NN
business.clear_default_repository_permissionAn enterprise owner cleared the base repository permission policy setting for an enterprise.YN
business.clear_disallowed_two_factor_methodsCleared two-factor authentication restrictions for an enterprise.NN
business.clear_members_can_create_reposAn enterprise owner cleared a restriction on repository creation in organizations in the enterprise.YN
business.code_quality_access_policy_updateThe policy for Code Quality access was updated for an enterprise.NN
business.code_quality_enablement_policy_updateThe policy for Code Quality enablement was updated for an enterprise.NN
business.code_scanning_ai_findings_policy_updateThe policy for Code scanning AI findings was updated for an enterprise.NN
business.code_scanning_autofix_policy_updateThe policy for Code scanning autofix was updated for an enterprise.NN
business.code_scanning_autofix_third_party_tools_policy_updateThe policy for Code scanning autofix third party tools was updated for an enterprise.NN
business.code_security_enablement_policy_updateThe policy for Code Security enablement was updated for an enterprise.NN
business.code_security_metered_usage_lockEnablement for Code Security features on new repositories has been locked for this enterprise.NN
business.code_security_metered_usage_unlockEnablement for Code Security features on new repositories has been unlocked for this enterprise.NN
business.connect_usage_metrics_exportServer statistics were exported for the enterprise.NN
business.convert_trialThe enterprise account on a trial of GitHub Enterprise Cloud was upgraded to a paid enterprise account.NN
business.createAn enterprise was created.YN
business.create_trialA trial of GitHub Enterprise Cloud began.YN
business.deleteThe enterprise was deleted.NY
business.delete_custom_imageA custom image was deleted for an enterprise.NN
business.delete_custom_image_versionA custom image version was deleted for an enterprise.NN
business.dependabot_alerts_repo_admin_enablement_policy_updateNN
business.disable_oidcOIDC single sign-on was disabled for an enterprise.NY
business.disable_open_scimSCIM provisioning for custom integrations that use the REST API was disabled for the enterprise.NN
business.disable_samlSAML single sign-on was disabled for an enterprise.NY
business.disable_source_ip_disclosureDisplay of IP addresses within audit log events for the enterprise was disabled.NN
business.disable_two_factor_requirementThe requirement for members to have two-factor authentication enabled to access an enterprise was disabled.NY
business.enable_oidcOIDC single sign-on was enabled for an enterprise.NN
business.enable_open_scimSCIM provisioning for custom integrations that use the REST API was enabled for the enterprise.NN
business.enable_samlSAML single sign-on was enabled for an enterprise.NN
business.enable_source_ip_disclosureDisplay of IP addresses within audit log events for the enterprise was enabled.NN
business.enable_two_factor_requirementThe requirement for members to have two-factor authentication enabled to access an enterprise was enabled.NN
business.enterprise_server_license_downloadA GitHub Enterprise Server license was downloaded.NN
business.enterprise_teams_limit_reachedAn enterprise has reached its enterprise teams limit.NN
business.enterprise_teams_limit_warningAn enterprise is approaching its enterprise teams limit.NN
business.expire_trialThe trial of GitHub Enterprise Cloud expired.NN
business.github_models_billing_disabledGitHub Models billing was disabled for the business.NN
business.github_models_billing_enabledGitHub Models billing was enabled for the business.NN
business.import_license_usageLicense usage information was imported from a GitHub Enterprise Server instance to an enterprise account on GitHub.com.NN
business.invite_adminAn invitation for someone to be an enterprise owner of an enterprise was sent.NY
business.invite_billing_managerAn invitation for someone to be a billing manager of an enterprise was sent.NY
business.invite_unaffiliated_memberAn invitation for someone to join an enterprise was sent.NN
business.members_can_update_protected_branches.clearAn enterprise owner unset a policy for whether members of an enterprise can update protected branches on repositories for individual organizations. Organization owners can choose whether to allow updating protected branches settings.YN
business.members_can_update_protected_branches.disableThe ability for enterprise members to update branch protection rules was disabled. Only enterprise owners can update protected branches.NY
business.members_can_update_protected_branches.enableThe ability for enterprise members to update branch protection rules was enabled. Enterprise owners and members can update protected branches.YN
business.members_limit_reachedAn enterprise has reached its members limit.NN
business.organizations_limit_reachedAn enterprise has reached its organizations limit.NN
business.organizations_limit_warningAn enterprise is approaching its organizations limit.NN
business.proxy_security_header_disabledThe proxy security header was disabled for an enterprise. All users on the network can now access GitHub, unless blocked by other means.NN
business.proxy_security_header_enabledThe proxy security header was enabled for an enterprise. When the header is provided in requests, only Enterprise Managed Users matching the header will be able to access GitHub.NN
business.proxy_security_header_unsatisfiedA user outside the enterprise tried to access GitHub while the proxy security header was enabled and provided in the request.NN
business.recovery_code_failedAn enterprise owner failed to sign into a enterprise with an external identity provider (IdP) using a recovery code.NN
business.recovery_code_usedAn enterprise owner successfully signed into an enterprise with an external identity provider (IdP) using a recovery code.NN
business.recovery_codes_downloadedAn enterprise owner downloaded the enterprise's SSO recovery codes.NY
business.recovery_codes_generatedAn enterprise owner generated the enterprise's SSO recovery codes.NY
business.recovery_codes_printedAn enterprise owner printed the enterprise's SSO recovery codes.NY
business.recovery_codes_viewedAn enterprise owner viewed the enterprise's SSO recovery codes.NY
business.remove_adminAn enterprise owner was removed from an enterprise.NN
business.remove_billing_managerA billing manager was removed from an enterprise.NN
business.remove_disallowed_two_factor_methodRemoved a two-factor authentication method restriction for an enterprise.NN
business.remove_memberA member was removed from an enterprise.NN
business.remove_organizationAn organization was removed from an enterprise.NY
business.remove_support_entitleeA support entitlement was removed from a member of an enterprise.NN
business.rename_slugThe slug for the enterprise URL was renamed.NN
business.restoreThe deleted enterprise was restored.NN
business.revoke_external_identityThe external identity for a member in an enterprise was revoked.NN
business.revoke_sso_sessionThe SAML single sign-on session for a member in an enterprise was revoked.NN
business.secret_protection_metered_usage_lockEnablement for Secret Protection features on new repositories has been locked for this enterprise.NN
business.secret_protection_metered_usage_unlockEnablement for Secret Protection features on new repositories has been unlocked for this enterprise.NN
business.secret_scanning_repo_admin_settings_policy_updateNN
business.security_center_export_code_scanning_metricsA CSV export was requested on the "CodeQL pull request alerts" page.NN
business.security_center_export_coverageA CSV export was requested on the "Coverage" page.NN
business.security_center_export_overview_dashboardA CSV export was requested on the "Overview Dashboard" page.NN
business.security_center_export_riskA CSV export was requested on the "Risk" page.NN
business.set_actions_cache_retention_policyThe cache retention policy for GitHub Actions was set for an enterprise.NN
business.set_actions_cache_storage_policyThe cache storage policy for GitHub Actions was set for an enterprise.NN
business.set_actions_fork_pr_approvals_policyThe policy for requiring approvals for workflows from public forks was changed for an enterprise.NN
business.set_actions_private_fork_pr_approvals_policyThe policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an enterprise.NN
business.set_actions_retention_limitThe retention period for GitHub Actions artifacts and logs was changed for an enterprise.NN
business.set_default_workflow_permissionsThe default permissions granted to the GITHUB_TOKEN when running workflows were changed for an enterprise.YN
business.set_fork_pr_workflows_policyThe policy for fork pull request workflows was changed for an enterprise.NN
business.set_workflow_permission_can_approve_prThe policy for allowing GitHub Actions to create and approve pull requests was changed for an enterprise.YN
business.sso_responseA SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your enterprise. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.NN
business.trial_email_verification_failedA trial email verification attempt failed for a GitHub Enterprise Cloud trial.NN
business.trial_email_verification_requestedA trial email verification resend was requested for a GitHub Enterprise Cloud trial.YN
business.trial_email_verification_sentA trial email verification was sent for a GitHub Enterprise Cloud trial.YN
business.trial_email_verifiedThe trial email was successfully verified for a GitHub Enterprise Cloud trial.YN
business.update_actions_settingsAn enterprise owner or site administrator updated GitHub Actions policy settings for an enterprise.NN
business.update_default_repository_permissionThe base repository permission setting was updated for all organizations in an enterprise.YN
business.update_emu_repo_self_hosted_runners_policyNN
business.update_member_repository_creation_permissionThe repository creation setting was updated for an enterprise.YN
business.update_member_repository_invitation_permissionThe policy setting for enterprise members inviting outside collaborators to repositories was updated.YN
business.update_repo_self_hosted_runners_policyNN
business.update_saml_provider_settingsThe SAML single sign-on provider settings for an enterprise were updated.NY
business.update_unaffiliated_users_policyThe policy for removing user accounts when removing the last organization membership was updated.NN
business.upgrade_from_organizationThe organization was upgraded to an enterprise account.NN

business.add_admin

#
Category
business

Description

An enterprise owner was added to an enterprise.

Documented on GitHub's enterprise audit log reference.

business.add_billing_manager

#
Category
business

Description

A billing manager was added to an enterprise.

Documented on GitHub's enterprise audit log reference.

business.add_disallowed_two_factor_method

#
Category
business

Description

An enterprise prevented access to resources by users with the given two-factor method.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.add_organization

#
Category
business

Description

An organization was added to an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783902059941,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDU=",
  "action": "business.add_organization",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902059941,
  "name": "example-business-2",
  "operation_type": "create",
  "org": "example-org",
  "org_id": 9000004,
  "organization_upgrade": false,
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.add_support_entitlee

#
Category
business

Description

A support entitlement was added to a member of an enterprise.

Documented on GitHub's enterprise audit log reference.

business.advanced_security_metered_usage_lock

#
Category
business

Description

Enablement for Advanced Security features on new repositories has been locked for this enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.advanced_security_metered_usage_unlock

#
Category
business

Description

Enablement for Advanced Security features on new repositories has been unlocked for this enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.advanced_security_policy_update

#
Category
business

Description

An enterprise owner created, updated, or removed a policy for GitHub Advanced Security.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.advanced_security_repo_admin_enablement_policy_update

#
Category
business

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.audit_log_export

#
Category
business

Description

An export of the enterprise audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.audit_log_git_event_export

#
Category
business

Description

An export of the enterprise's Git events was created.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.cancel_admin_invitation

#
Category
business

Description

An invitation for someone to be an owner of an enterprise was canceled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.cancel_billing_manager_invitation

#
Category
business

Description

An invitation for someone to be an billing manager of an enterprise was canceled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.cancel_trial

#
Category
business

Description

The trial of GitHub Enterprise Cloud was canceled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.change_seats_plan_type

#
Category
business

Description

The seats plan type was changed for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.clear_actions_settings

#
Category
business

Description

An enterprise owner or site administrator cleared GitHub Actions policy settings for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.clear_default_repository_permission

#
Category
business

Description

An enterprise owner cleared the base repository permission policy setting for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783955163543,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDM=",
  "action": "business.clear_default_repository_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783955163543,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "name": "example-business-2",
  "operation_type": "modify",
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "94CE:3FE560:EE07A77:F2C4D48:6A54FEDB",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

References #

business.clear_disallowed_two_factor_methods

#
Category
business

Description

Cleared two-factor authentication restrictions for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.clear_members_can_create_repos

#
Category
business

Description

An enterprise owner cleared a restriction on repository creation in organizations in the enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783955164200,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDE=",
  "action": "business.clear_members_can_create_repos",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783955164200,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "name": "example-business-2",
  "operation_type": "modify",
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "94CE:3FE560:EE07E27:F2C50EF:6A54FEDB",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2",
  "visibility": null
}

References #

business.code_quality_access_policy_update

#
Category
business

Description

The policy for Code Quality access was updated for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.code_quality_enablement_policy_update

#
Category
business

Description

The policy for Code Quality enablement was updated for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.code_scanning_ai_findings_policy_update

#
Category
business

Description

The policy for Code scanning AI findings was updated for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.code_scanning_autofix_policy_update

#
Category
business

Description

The policy for Code scanning autofix was updated for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.code_scanning_autofix_third_party_tools_policy_update

#
Category
business

Description

The policy for Code scanning autofix third party tools was updated for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.code_security_enablement_policy_update

#
Category
business

Description

The policy for Code Security enablement was updated for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.code_security_metered_usage_lock

#
Category
business

Description

Enablement for Code Security features on new repositories has been locked for this enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.code_security_metered_usage_unlock

#
Category
business

Description

Enablement for Code Security features on new repositories has been unlocked for this enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.connect_usage_metrics_export

#
Category
business

Description

Server statistics were exported for the enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.convert_trial

#
Category
business

Description

The enterprise account on a trial of GitHub Enterprise Cloud was upgraded to a paid enterprise account.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.create

#
Category
business

Description

An enterprise was created.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783902030764,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTM=",
  "action": "business.create",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902030764,
  "name": "example-business-2",
  "operation_type": "create",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.create_trial

#
Category
business

Description

A trial of GitHub Enterprise Cloud began.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783902030990,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTA=",
  "action": "business.create_trial",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902030990,
  "name": "example-business-2",
  "operation_type": "create",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.delete

#
Category
business

Description

The enterprise was deleted.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.delete_custom_image

#
Category
business

Description

A custom image was deleted for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.delete_custom_image_version

#
Category
business

Description

A custom image version was deleted for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.dependabot_alerts_repo_admin_enablement_policy_update

#
Category
business

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.disable_oidc

#
Category
business

Description

OIDC single sign-on was disabled for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

business.disable_open_scim

#
Category
business

Description

SCIM provisioning for custom integrations that use the REST API was disabled for the enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.disable_saml

#
Category
business

Description

SAML single sign-on was disabled for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

business.disable_source_ip_disclosure

#
Category
business

Description

Display of IP addresses within audit log events for the enterprise was disabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.disable_two_factor_requirement

#
Category
business

Description

The requirement for members to have two-factor authentication enabled to access an enterprise was disabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • GitHub Enterprise Disable 2FA Requirement source: The following analytic detects when two-factor authentication (2FA) requirements are disabled in GitHub Enterprise. The detection monitors GitHub Enterprise audit logs for 2FA requirement changes by tracking actor details, organization…T1195, T1685

YARA-L #

Panther #

business.enable_oidc

#
Category
business

Description

OIDC single sign-on was enabled for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.enable_open_scim

#
Category
business

Description

SCIM provisioning for custom integrations that use the REST API was enabled for the enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.enable_saml

#
Category
business

Description

SAML single sign-on was enabled for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.enable_source_ip_disclosure

#
Category
business

Description

Display of IP addresses within audit log events for the enterprise was enabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.enable_two_factor_requirement

#
Category
business

Description

The requirement for members to have two-factor authentication enabled to access an enterprise was enabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.enterprise_server_license_download

#
Category
business

Description

A GitHub Enterprise Server license was downloaded.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.enterprise_teams_limit_reached

#
Category
business

Description

An enterprise has reached its enterprise teams limit.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.enterprise_teams_limit_warning

#
Category
business

Description

An enterprise is approaching its enterprise teams limit.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.expire_trial

#
Category
business

Description

The trial of GitHub Enterprise Cloud expired.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.github_models_billing_disabled

#
Category
business

Description

GitHub Models billing was disabled for the business.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.github_models_billing_enabled

#
Category
business

Description

GitHub Models billing was enabled for the business.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.import_license_usage

#
Category
business

Description

License usage information was imported from a GitHub Enterprise Server instance to an enterprise account on GitHub.com.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.invite_admin

#
Category
business

Description

An invitation for someone to be an enterprise owner of an enterprise was sent.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.invite_billing_manager

#
Category
business

Description

An invitation for someone to be a billing manager of an enterprise was sent.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.invite_unaffiliated_member

#
Category
business

Description

An invitation for someone to join an enterprise was sent.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.members_can_update_protected_branches.clear

#
Category
business

Description

An enterprise owner unset a policy for whether members of an enterprise can update protected branches on repositories for individual organizations. Organization owners can choose whether to allow updating protected branches settings.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783955167529,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMzA=",
  "action": "business.members_can_update_protected_branches.clear",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783955167529,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "name": "example-business-2",
  "operation_type": "modify",
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "94CE:3FE560:EE0907E:F2C63B8:6A54FEDF",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user": "user",
  "user_agent": "python-requests/2.34.2",
  "user_id": 9000002
}

References #

business.members_can_update_protected_branches.disable

#
Category
business

Description

The ability for enterprise members to update branch protection rules was disabled. Only enterprise owners can update protected branches.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

business.members_can_update_protected_branches.enable

#
Category
business

Description

The ability for enterprise members to update branch protection rules was enabled. Enterprise owners and members can update protected branches.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783955167237,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMzE=",
  "action": "business.members_can_update_protected_branches.enable",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783955167237,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "name": "example-business-2",
  "operation_type": "modify",
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "94CE:3FE560:EE08E95:F2C61DD:6A54FEDF",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user": "user",
  "user_agent": "python-requests/2.34.2",
  "user_id": 9000002
}

References #

business.members_limit_reached

#
Category
business

Description

An enterprise has reached its members limit.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.organizations_limit_reached

#
Category
business

Description

An enterprise has reached its organizations limit.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.organizations_limit_warning

#
Category
business

Description

An enterprise is approaching its organizations limit.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.proxy_security_header_disabled

#
Category
business

Description

The proxy security header was disabled for an enterprise. All users on the network can now access GitHub, unless blocked by other means.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.proxy_security_header_enabled

#
Category
business

Description

The proxy security header was enabled for an enterprise. When the header is provided in requests, only Enterprise Managed Users matching the header will be able to access GitHub.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.proxy_security_header_unsatisfied

#
Category
business

Description

A user outside the enterprise tried to access GitHub while the proxy security header was enabled and provided in the request.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.recovery_code_failed

#
Category
business

Description

An enterprise owner failed to sign into a enterprise with an external identity provider (IdP) using a recovery code.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.recovery_code_used

#
Category
business

Description

An enterprise owner successfully signed into an enterprise with an external identity provider (IdP) using a recovery code.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.recovery_codes_downloaded

#
Category
business

Description

An enterprise owner downloaded the enterprise's SSO recovery codes.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.recovery_codes_generated

#
Category
business

Description

An enterprise owner generated the enterprise's SSO recovery codes.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.recovery_codes_printed

#
Category
business

Description

An enterprise owner printed the enterprise's SSO recovery codes.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.recovery_codes_viewed

#
Category
business

Description

An enterprise owner viewed the enterprise's SSO recovery codes.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.remove_admin

#
Category
business

Description

An enterprise owner was removed from an enterprise.

Documented on GitHub's enterprise audit log reference.

business.remove_billing_manager

#
Category
business

Description

A billing manager was removed from an enterprise.

Documented on GitHub's enterprise audit log reference.

business.remove_disallowed_two_factor_method

#
Category
business

Description

Removed a two-factor authentication method restriction for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.remove_member

#
Category
business

Description

A member was removed from an enterprise.

Documented on GitHub's enterprise audit log reference.

business.remove_organization

#
Category
business

Description

An organization was removed from an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • GitHub Enterprise Remove Organization source: The following analytic detects when a user removes an organization from GitHub Enterprise. The detection monitors GitHub Enterprise audit logs for organization deletion events, which could indicate unauthorized removal of critical business…T1195, T1485

YARA-L #

business.remove_support_entitlee

#
Category
business

Description

A support entitlement was removed from a member of an enterprise.

Documented on GitHub's enterprise audit log reference.

business.rename_slug

#
Category
business

Description

The slug for the enterprise URL was renamed.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.restore

#
Category
business

Description

The deleted enterprise was restored.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.revoke_external_identity

#
Category
business

Description

The external identity for a member in an enterprise was revoked.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.revoke_sso_session

#
Category
business

Description

The SAML single sign-on session for a member in an enterprise was revoked.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.secret_protection_metered_usage_lock

#
Category
business

Description

Enablement for Secret Protection features on new repositories has been locked for this enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.secret_protection_metered_usage_unlock

#
Category
business

Description

Enablement for Secret Protection features on new repositories has been unlocked for this enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.secret_scanning_repo_admin_settings_policy_update

#
Category
business

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.security_center_export_code_scanning_metrics

#
Category
business

Description

A CSV export was requested on the "CodeQL pull request alerts" page.

Documented on GitHub's enterprise audit log reference.

business.security_center_export_coverage

#
Category
business

Description

A CSV export was requested on the "Coverage" page.

Documented on GitHub's enterprise audit log reference.

business.security_center_export_overview_dashboard

#
Category
business

Description

A CSV export was requested on the "Overview Dashboard" page.

Documented on GitHub's enterprise audit log reference.

business.security_center_export_risk

#
Category
business

Description

A CSV export was requested on the "Risk" page.

Documented on GitHub's enterprise audit log reference.

business.set_actions_cache_retention_policy

#
Category
business

Description

The cache retention policy for GitHub Actions was set for an enterprise.

Documented on GitHub's enterprise audit log reference.

business.set_actions_cache_storage_policy

#
Category
business

Description

The cache storage policy for GitHub Actions was set for an enterprise.

Documented on GitHub's enterprise audit log reference.

business.set_actions_fork_pr_approvals_policy

#
Category
business

Description

The policy for requiring approvals for workflows from public forks was changed for an enterprise.

Documented on GitHub's enterprise audit log reference.

business.set_actions_private_fork_pr_approvals_policy

#
Category
business

Description

The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an enterprise.

Documented on GitHub's enterprise audit log reference.

business.set_actions_retention_limit

#
Category
business

Description

The retention period for GitHub Actions artifacts and logs was changed for an enterprise.

Documented on GitHub's enterprise audit log reference.

business.set_default_workflow_permissions

#
Category
business

Description

The default permissions granted to the GITHUB_TOKEN when running workflows were changed for an enterprise.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783902030910,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTE=",
  "action": "business.set_default_workflow_permissions",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902030910,
  "name": "example-business-2",
  "operation_type": "modify",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.set_fork_pr_workflows_policy

#
Category
business

Description

The policy for fork pull request workflows was changed for an enterprise.

Documented on GitHub's enterprise audit log reference.

business.set_workflow_permission_can_approve_pr

#
Category
business

Description

The policy for allowing GitHub Actions to create and approve pull requests was changed for an enterprise.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783902030884,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNTI=",
  "action": "business.set_workflow_permission_can_approve_pr",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902030884,
  "name": "example-business-2",
  "operation_type": "modify",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.sso_response

#
Category
business

Description

A SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your enterprise. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.trial_email_verification_failed

#
Category
business

Description

A trial email verification attempt failed for a GitHub Enterprise Cloud trial.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.trial_email_verification_requested

#
Category
business

Description

A trial email verification resend was requested for a GitHub Enterprise Cloud trial.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783902031677,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDk=",
  "action": "business.trial_email_verification_requested",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902031677,
  "name": "example-business-2",
  "operation_type": "create",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.trial_email_verification_sent

#
Category
business

Description

A trial email verification was sent for a GitHub Enterprise Cloud trial.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783902031686,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDg=",
  "action": "business.trial_email_verification_sent",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902031686,
  "name": "example-business-2",
  "operation_type": "create",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B1DC87:7F4640F:6A542F3C",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.trial_email_verified

#
Category
business

Description

The trial email was successfully verified for a GitHub Enterprise Cloud trial.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783902041198,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDc=",
  "action": "business.trial_email_verified",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902041198,
  "name": "example-business-2",
  "operation_type": "modify",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B20635:7F48F01:6A542F4F",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

References #

business.update_actions_settings

#
Category
business

Description

An enterprise owner or site administrator updated GitHub Actions policy settings for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.update_default_repository_permission

#
Category
business

Description

The base repository permission setting was updated for all organizations in an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783955163225,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDQ=",
  "action": "business.update_default_repository_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783955163225,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "name": "example-business-2",
  "old_permission": "no_policy",
  "operation_type": "modify",
  "permission": "read",
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "94CE:3FE560:EE07847:F2C4B40:6A54FEDA",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

References #

business.update_emu_repo_self_hosted_runners_policy

#
Category
business

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.update_member_repository_creation_permission

#
Category
business

Description

The repository creation setting was updated for an enterprise.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783955163886,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxNDI=",
  "action": "business.update_member_repository_creation_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783955163886,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "name": "example-business-2",
  "operation_type": "modify",
  "permission": true,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "94CE:3FE560:EE07C0E:F2C4ECD:6A54FEDB",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2",
  "visibility": "none"
}

References #

business.update_member_repository_invitation_permission

#
Category
business

Description

The policy setting for enterprise members inviting outside collaborators to repositories was updated.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Example Audit Log Entry #

{
  "@timestamp": 1783955166130,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMzQ=",
  "action": "business.update_member_repository_invitation_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783955166130,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "name": "example-business-2",
  "operation_type": "modify",
  "permission": true,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "94CE:3FE560:EE088E5:F2C5C00:6A54FEDD",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

References #

business.update_repo_self_hosted_runners_policy

#
Category
business

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.update_saml_provider_settings

#
Category
business

Description

The SAML single sign-on provider settings for an enterprise were updated.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

business.update_unaffiliated_users_policy

#
Category
business

Description

The policy for removing user accounts when removing the last organization membership was updated.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

business.upgrade_from_organization

#
Category
business

Description

The organization was upgraded to an enterprise account.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.