IP Allow List

actionDescriptionSampleRule
ip_allow_list.disableAn IP allow list was disabled.NY
ip_allow_list.disable_for_installed_appsAn IP allow list was disabled for installed GitHub Apps.NY
ip_allow_list.disable_idp_ip_allowlist_for_webIdentity Provider based IP allow list for web interactions was disabled.NY
ip_allow_list.disable_skip_idp_ip_allowlist_app_accessNY
ip_allow_list.disable_user_level_enforcementIP allow list user level enforcement was disabled.NY
ip_allow_list.enableAn IP allow list was enabled.NY
ip_allow_list.enable_for_installed_appsAn IP allow list was enabled for installed GitHub Apps.NY
ip_allow_list.enable_idp_ip_allowlist_for_webIdentity Provider based IP allow list for web interactions was enabled.NY
ip_allow_list.enable_skip_idp_ip_allowlist_app_accessNY
ip_allow_list.enable_user_level_enforcementIP allow list user level enforcement was enabled.NY
ip_allow_list.update_ip_allowlist_configurationNY

ip_allow_list.disable

#
Category
ip-allow-list

Description

An IP allow list was disabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • GitHub Enterprise Disable IP Allow List source: The following analytic identifies when an IP allow list is disabled in GitHub Enterprise. The detection monitors GitHub Enterprise audit logs for actions related to disabling IP allow lists at the organization or enterprise level. This…T1195, T1685

Panther #

ip_allow_list.disable_for_installed_apps

#
Category
ip-allow-list

Description

An IP allow list was disabled for installed GitHub Apps.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.disable_idp_ip_allowlist_for_web

#
Category
ip-allow-list

Description

Identity Provider based IP allow list for web interactions was disabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.disable_skip_idp_ip_allowlist_app_access

#
Category
ip-allow-list

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.disable_user_level_enforcement

#
Category
ip-allow-list

Description

IP allow list user level enforcement was disabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.enable

#

ip_allow_list.enable_for_installed_apps

#
Category
ip-allow-list

Description

An IP allow list was enabled for installed GitHub Apps.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.enable_idp_ip_allowlist_for_web

#
Category
ip-allow-list

Description

Identity Provider based IP allow list for web interactions was enabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.enable_skip_idp_ip_allowlist_app_access

#
Category
ip-allow-list

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.enable_user_level_enforcement

#
Category
ip-allow-list

Description

IP allow list user level enforcement was enabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ip_allow_list.update_ip_allowlist_configuration

#
Category
ip-allow-list

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #