IP Allow List
| action | Description | Sample | Rule |
|---|---|---|---|
| ip_ | An IP allow list was disabled. | N | Y |
| ip_ | An IP allow list was disabled for installed GitHub Apps. | N | Y |
| ip_ | Identity Provider based IP allow list for web interactions was disabled. | N | Y |
| ip_ | N | Y | |
| ip_ | IP allow list user level enforcement was disabled. | N | Y |
| ip_ | An IP allow list was enabled. | N | Y |
| ip_ | An IP allow list was enabled for installed GitHub Apps. | N | Y |
| ip_ | Identity Provider based IP allow list for web interactions was enabled. | N | Y |
| ip_ | N | Y | |
| ip_ | IP allow list user level enforcement was enabled. | N | Y |
| ip_ | N | Y |
ip_allow_list.disable
#Description
An IP allow list was disabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Splunk #
T1195, T1685Panther #
T1098↳ also matches ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_for_installed_apps
#Description
An IP allow list was disabled for installed GitHub Apps.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_idp_ip_allowlist_for_web
#Description
Identity Provider based IP allow list for web interactions was disabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_skip_idp_ip_allowlist_app_access
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_user_level_enforcement
#Description
IP allow list user level enforcement was disabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.enable
#Description
An IP allow list was enabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.enable_for_installed_apps
#Description
An IP allow list was enabled for installed GitHub Apps.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.enable_idp_ip_allowlist_for_web
#Description
Identity Provider based IP allow list for web interactions was enabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.enable_skip_idp_ip_allowlist_app_access
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.enable_user_level_enforcement
#Description
IP allow list user level enforcement was enabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.update_ip_allowlist_configuration
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more