Org

actionDescriptionSampleRule
org.accept_business_invitationAn invitation sent to an organization to join an enterprise was accepted.NY
org.add_billing_managerA billing manager was added to an organization.NY
org.add_disallowed_two_factor_methodAn organization prevented access to resources by users with the given two-factor method.NY
org.add_memberA user joined an organization.YY
org.add_outside_collaboratorAn outside collaborator was added to a repository.YY
org.add_security_managerYY
org.advanced_security_disabled_for_new_reposGitHub Advanced Security was disabled for new repositories in an organization.YY
org.advanced_security_disabled_on_all_reposGitHub Advanced Security was disabled for all repositories in an organization.NY
org.advanced_security_enabled_for_new_reposGitHub Advanced Security was enabled for new repositories in an organization.YY
org.advanced_security_enabled_on_all_reposGitHub Advanced Security was enabled for all repositories in an organization.NY
org.advanced_security_entity_policy_updateAn enterprise owner updated the GitHub Advanced Security access policy for repositories owned by the organization.NY
org.advanced_security_policy_selected_member_disabledAn enterprise owner prevented GitHub Advanced Security features from being enabled for repositories owned by the organization.NY
org.advanced_security_policy_selected_member_enabledAn enterprise owner allowed GitHub Advanced Security features to be enabled for repositories owned by the organization.NY
org.allow_third_party_access_requests_from_outside_collaborators_disabledThird-party application access for outside collaborators was disabled for the organization.NY
org.allow_third_party_access_requests_from_outside_collaborators_enabledThird-party application access for outside collaborators was enabled for the organization.NY
org.archiveThe organization was archived.NY
org.audit_log_exportAn export of the organization audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query.YY
org.audit_log_git_event_exportAn export of the organization's Git events was created.NY
org.billing_signup_errorNY
org.block_userAn organization owner blocked a user from accessing the organization's repositories.YY
org.cancel_business_invitationAn invitation for an organization to join an enterprise was revokedNY
org.cancel_invitationAn invitation sent to a user to join an organization was revoked.YY
org.clear_custom_invitation_rate_limitNY
org.clear_disallowed_two_factor_methodsCleared two-factor authentication restrictions for an organization.NY
org.code_quality_entity_policy_updateAn organization owner updated the Code Quality entity policy for repositories owned by the organization.NY
org.code_scanning_ai_findings_disabledAI-powered findings for code scanning were disabled for an organization.NY
org.code_scanning_ai_findings_enabledAI-powered findings for code scanning were enabled for an organization.NY
org.code_scanning_autofix_disabledAutofix for code scanning alerts was disabled for an organization.NY
org.code_scanning_autofix_enabledAutofix for code scanning alerts was enabled for an organization.NY
org.code_scanning_autofix_third_party_tools_disabledAutofix for third party tools for code scanning alerts was disabled for an organization.NY
org.code_scanning_autofix_third_party_tools_enabledAutofix for third party tools for code scanning alerts was enabled for an organization.NY
org.code_scanning_scan_inactive_repos_disabledScanning inactive repositories was disabled for an organization.NY
org.code_scanning_scan_inactive_repos_enabledScanning inactive repositories was enabled for an organization.NY
org.code_security_metered_usage_lockEnablement for Code Security features on new repositories has been locked for this organization.NY
org.code_security_metered_usage_unlockEnablement for Code Security features on new repositories has been unlocked for this organization.NY
org.codeql_disabledCode scanning using the default setup was disabled for an organization.NY
org.codeql_enabledCode scanning using the default setup was enabled for an organization.NY
org.codespaces_access_updatedAccess to use Codespaces on internal and private repositories was updated for an organization.NY
org.codespaces_ownership_updatedOwnership and payment for codespaces was updated for an organization.YY
org.codespaces_team_access_allowedA team has been allowed to use Codespaces for an organization.NY
org.codespaces_team_access_revokedA team has been prevented from using Codespaces for an organization.NY
org.codespaces_trusted_repo_access_grantedGitHub Codespaces was granted trusted repository access to all other repositories in an organization.NY
org.codespaces_trusted_repo_access_revokedGitHub Codespaces trusted repository access to all other repositories in an organization was revoked.NY
org.codespaces_user_access_allowedA user has been allowed to use Codespaces for an organization.NY
org.codespaces_user_access_revokedA user has been prevented from using Codespaces for an organization.NY
org.config.disable_collaborators_onlyThe interaction limit for collaborators only for an organization was disabled.NY
org.config.disable_contributors_onlyThe interaction limit for prior contributors only for an organization was disabled.NY
org.config.disable_sockpuppet_disallowedThe interaction limit for existing users only for an organization was disabled.NY
org.config.enable_collaborators_onlyThe interaction limit for collaborators only for an organization was enabled.NY
org.config.enable_contributors_onlyThe interaction limit for prior contributors only for an organization was enabled.NY
org.config.enable_sockpuppet_disallowedThe interaction limit for existing users only for an organization was enabled.NY
org.configure_self_hosted_jit_runnerA new just-in-time GitHub Actions self-hosted runner was configuredNY
org.confirm_business_invitationAn invitation for an organization to join an enterprise was confirmed.NY
org.connect_usage_metrics_exportServer statistics were exported for the organization.NY
org.createAn organization was created.YY
org.create_actions_secretA GitHub Actions secret was created for an organization.YY
org.create_actions_variableA GitHub Actions variable was created for an organization.YY
org.create_integration_secretA Codespaces or Dependabot secret was created for an organization.NY
org.deleteAn organization was deleted by a user or staff.NY
org.delete_custom_imageA custom image was deleted for an organization.NY
org.delete_custom_image_versionA custom image version was deleted for an organization.NY
org.disable_member_team_creation_permissionTeam creation was limited to owners.YY
org.disable_oauth_app_restrictionsThird-party application access restrictions for an organization were disabled.NY
org.disable_reader_discussion_creation_permissionAn organization owner limited discussion creation to users with at least triage permission in an organization.NY
org.disable_samlSAML single sign-on was disabled for an organization.NY
org.disable_source_ip_disclosureDisplay of IP addresses within audit log events for the organization was disabled.NY
org.disable_two_factor_requirementA two-factor authentication requirement was disabled for the organization.NY
org.display_commenter_full_name_disabledAn organization owner disabled the display of a commenter's full name in an organization. Members cannot see a comment author's full name.NY
org.display_commenter_full_name_enabledAn organization owner enabled the display of a commenter's full name in an organization. Members can see a comment author's full name.NY
org.enable_member_team_creation_permissionTeam creation by members was allowed.YY
org.enable_oauth_app_restrictionsThird-party application access restrictions for an organization were enabled.NY
org.enable_reader_discussion_creation_permissionAn organization owner allowed users with read access to create discussions in an organizationNY
org.enable_samlSAML single sign-on was enabled for the organization.NY
org.enable_source_ip_disclosureDisplay of IP addresses within audit log events for the organization was enabled.NY
org.enable_two_factor_requirementTwo-factor authentication is now required for the organization.NY
org.integration_manager_addedAn organization owner granted a member access to manage all GitHub Apps owned by an organization.NY
org.integration_manager_removedAn organization owner removed access to manage all GitHub Apps owned by an organization from an organization member.NY
org.invite_memberA new user was invited to join an organization.YY
org.invite_to_businessAn organization was invited to join an enterprise.NY
org.members_can_update_protected_branches.disableThe ability for enterprise members to update protected branches was disabled. Only enterprise owners can update protected branches.NY
org.members_can_update_protected_branches.enableThe ability for enterprise members to update protected branches was enabled. Members of an organization can update protected branches.NY
org.members_limit_warningAn organization is approaching its members limit.NY
org.oauth_app_access_approvedAccess to an organization was granted for an OAuth App.YY
org.oauth_app_access_blockedNY
org.oauth_app_access_deniedAccess was disabled for an OAuth App that was previously approved.NY
org.oauth_app_access_requestedAn organization member requested that an owner grant an OAuth App access to an organization.YY
org.oauth_app_access_unblockedNY
org.rate_limited_invitesNY
org.recovery_code_failedAn organization owner failed to sign into a organization with an external identity provider (IdP) using a recovery code.NY
org.recovery_code_usedAn organization owner successfully signed into an organization with an external identity provider (IdP) using a recovery code.NY
org.recovery_codes_downloadedAn organization owner downloaded the organization's SSO recovery codes.NY
org.recovery_codes_generatedAn organization owner generated the organization's SSO recovery codes.NY
org.recovery_codes_printedAn organization owner printed the organization's SSO recovery codes.NY
org.recovery_codes_viewedAn organization owner viewed the organization's SSO recovery codes.NY
org.register_self_hosted_runnerA new self-hosted runner was registered.NY
org.remove_actions_secretA GitHub Actions secret was removed from an organization.YY
org.remove_actions_variableA GitHub Actions variable was removed from an organization.YY
org.remove_billing_managerA billing manager was removed from an organization, either manually or due to a two-factor authentication requirement.NY
org.remove_disallowed_two_factor_methodRemoved a two-factor authentication method restriction for an organization.NY
org.remove_integration_secretA Codespaces or Dependabot secret was removed from an organization.NY
org.remove_memberA member was removed from an organization, either manually or due to a two-factor authentication requirement.YY
org.remove_outside_collaboratorAn outside collaborator was removed from an organization, either manually or due to a two-factor authentication requirement.NY
org.remove_security_managerYY
org.remove_self_hosted_runnerA self-hosted runner was removed.NY
org.renameAn organization was renamed.NY
org.required_workflow_createTriggered when a required workflow is created.NY
org.required_workflow_deleteTriggered when a required workflow is deleted.NY
org.required_workflow_updateTriggered when a required workflow is updated.NY
org.restore_memberAn organization member was restored.YY
org.revoke_external_identityA member's linked identity was revoked.NY
org.revoke_sso_sessionA member's SAML session was revoked.NY
org.runner_group_createdA self-hosted runner group was created.YY
org.runner_group_removedA self-hosted runner group was removed.YY
org.runner_group_renamedA self-hosted runner group was renamed.NY
org.runner_group_runner_removedThe REST API was used to remove a self-hosted runner from a group.NY
org.runner_group_runners_addedA self-hosted runner was added to a group.NY
org.runner_group_runners_updatedA runner group's list of members was updated.NY
org.runner_group_updatedThe configuration of a self-hosted runner group was changed.YY
org.runner_group_visiblity_updatedThe visibility of a self-hosted runner group was updated via the REST API.NY
org.secret_protection_metered_usage_lockEnablement for Secret Protection features on new repositories has been locked for this organization.NY
org.secret_protection_metered_usage_unlockEnablement for Secret Protection features on new repositories has been unlocked for this organization.NY
org.secret_scanning_custom_pattern_push_protection_disabledPush protection for a custom pattern for secret scanning was disabled for an organization.NY
org.secret_scanning_custom_pattern_push_protection_enabledPush protection for a custom pattern for secret scanning was enabled for an organization.NY
org.secret_scanning_push_protection_custom_message_disabledThe custom message triggered by an attempted push to a push-protected repository was disabled for an organization.YY
org.secret_scanning_push_protection_custom_message_enabledThe custom message triggered by an attempted push to a push-protected repository was enabled for an organization.YY
org.secret_scanning_push_protection_custom_message_updatedThe custom message triggered by an attempted push to a push-protected repository was updated for an organization.YY
org.secret_scanning_push_protection_disablePush protection for secret scanning was disabled.NY
org.secret_scanning_push_protection_enablePush protection for secret scanning was enabled.NY
org.secret_scanning_push_protection_new_repos_disablePush protection for secret scanning was disabled for all new repositories in the organization.YY
org.secret_scanning_push_protection_new_repos_enablePush protection for secret scanning was enabled for all new repositories in the organization.YY
org.security_center_export_code_scanning_metricsA CSV export was requested on the CodeQL pull request alerts page.NY
org.security_center_export_coverageA CSV export was requested on the Coverage page.NY
org.security_center_export_overview_dashboardA CSV export was requested on the Overview Dashboard page.NY
org.security_center_export_riskA CSV export was requested on the Risk page.NY
org.self_hosted_runner_offlineThe runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.NY
org.self_hosted_runner_onlineThe runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.NY
org.self_hosted_runner_updatedThe runner application was updated. This event is not included in the JSON/CSV export.NY
org.set_actions_cache_retention_policyThe cache retention policy for GitHub Actions was set for an organization.NY
org.set_actions_cache_storage_policyThe cache storage policy for GitHub Actions was set for an organization.NY
org.set_actions_fork_pr_approvals_policyThe setting for requiring approvals for workflows from public forks was changed for an organization.NY
org.set_actions_private_fork_pr_approvals_policyThe policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an organization.NY
org.set_actions_retention_limitThe retention period for GitHub Actions artifacts and logs in an organization was changed.NY
org.set_custom_invitation_rate_limitNY
org.set_default_workflow_permissionsThe default permissions granted to the GITHUB_TOKEN when running workflows were changed for an organization.YY
org.set_fork_pr_workflows_policyThe policy for workflows on private repository forks was changed.NY
org.set_workflow_permission_can_approve_prThe policy for allowing GitHub Actions to create and approve pull requests was changed for an organization.YY
org.sso_responseA SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your organization. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.YY
org.transferAn organization was transferred between enterprise accounts.NY
org.transfer_outgoingAn organization was transferred between enterprise accounts.NY
org.unarchiveThe organization was unarchived.NY
org.unblock_userA user was unblocked from an organization.YY
org.update_actions_secretA GitHub Actions secret was updated for an organization.YY
org.update_actions_settingsAn organization owner or site administrator updated GitHub Actions policy settings for an organization.YY
org.update_actions_variableA GitHub Actions variable was updated for an organization.YY
org.update_custom_images_policyThe enterprise updated GitHub Actions custom image policy settings for an organization.NY
org.update_default_repository_permissionThe default repository permission level for organization members was changed.YY
org.update_immutable_releases_settings_policyThe settings policy for immutable releases was updated for an organization.NY
org.update_integration_secretA Codespaces or Dependabot secret was updated for an organization.NY
org.update_memberA person's role was changed from owner to member or member to owner.YY
org.update_member_repository_creation_permissionThe create repository permission for organization members was changed.YY
org.update_member_repository_invitation_permissionAn organization owner changed the policy setting for organization members inviting outside collaborators to repositories.YY
org.update_new_repository_default_branch_settingThe name of the default branch was changed for new repositories in the organization.NY
org.update_repo_self_hosted_runners_policyThe repository self-hosted runners policy was updatedNY
org.update_saml_provider_settingsAn organization's SAML provider settings were updated.YY
org.update_terms_of_serviceAn organization changed between the Standard Terms of Service and the GitHub Customer Agreement.NY

org.accept_business_invitation

#
Category
org

Description

An invitation sent to an organization to join an enterprise was accepted.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.add_billing_manager

#
Category
org

Description

A billing manager was added to an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.add_disallowed_two_factor_method

#
Category
org

Description

An organization prevented access to resources by users with the given two-factor method.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.add_member

#
Category
org

Description

A user joined an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000097,
  "user_id": 9000115,
  "actor_id": 9000031,
  "created_at": 1781023684187.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "invitation_id": 9000116,
  "org": "example-org",
  "user": "user",
  "actor": "user",
  "action": "org.add_member",
  "business": "example-business",
  "permission": "read",
  "request_id": 9000117,
  "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36 Edg/ip-redacted",
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
github.permission (elastic rule field)eqadmin1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

Panther #

References #

org.add_outside_collaborator

#
Category
org

Description

An outside collaborator was added to a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000092,
  "repo_id": 9000118,
  "actor_id": 9000119,
  "created_at": 1782224607048.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "org.add_outside_collaborator",
  "invitee": "user",
  "inviter": "user",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "permission": "read",
  "request_id": 9000120,
  "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.add_security_manager

#
Category
org

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957680008,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMTU=",
  "action": "org.add_security_manager",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957680008,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "create",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "BF08:15A139:F701C69:FBCAFFB:6A5508AF",
  "team": "example-business-3/example-team-16",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.advanced_security_disabled_for_new_repos

#
Category
org

Description

GitHub Advanced Security was disabled for new repositories in an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957527906,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTk=",
  "action": "org.advanced_security_disabled_for_new_repos",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957527906,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4C0B35:F98D04F:6A550817",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

References #

org.advanced_security_disabled_on_all_repos

#
Category
org

Description

GitHub Advanced Security was disabled for all repositories in an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.advanced_security_enabled_for_new_repos

#
Category
org

Description

GitHub Advanced Security was enabled for new repositories in an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957527504,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjA=",
  "action": "org.advanced_security_enabled_for_new_repos",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957527504,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4C08AF:F98CD9A:6A550817",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.advanced_security_enabled_on_all_repos

#
Category
org

Description

GitHub Advanced Security was enabled for all repositories in an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.advanced_security_entity_policy_update

#
Category
org

Description

An enterprise owner updated the GitHub Advanced Security access policy for repositories owned by the organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.advanced_security_policy_selected_member_disabled

#
Category
org

Description

An enterprise owner prevented GitHub Advanced Security features from being enabled for repositories owned by the organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.advanced_security_policy_selected_member_enabled

#
Category
org

Description

An enterprise owner allowed GitHub Advanced Security features to be enabled for repositories owned by the organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.allow_third_party_access_requests_from_outside_collaborators_disabled

#
Category
org

Description

Third-party application access for outside collaborators was disabled for the organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.allow_third_party_access_requests_from_outside_collaborators_enabled

#
Category
org

Description

Third-party application access for outside collaborators was enabled for the organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.archive

#
Category
org

Description

The organization was archived.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.audit_log_export

#
Category
org

Description

An export of the organization audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "actor_id": 9000121,
  "created_at": 1782855852272.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "actor": "user",
  "action": "org.audit_log_export",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000122,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "query_phrase": "actor:user ",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.audit_log_git_event_export

#
Category
org

Description

An export of the organization's Git events was created.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.billing_signup_error

#
Category
org

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.block_user

#
Category
org

Description

An organization owner blocked a user from accessing the organization's repositories.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783960672700,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMDI=",
  "action": "org.block_user",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "blocked_user": "user",
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783960672700,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "create",
  "org": "example-org",
  "org_id": 9000002,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "9562:3D1F96:F8FAFB2:FDD48B2:6A551460",
  "token_id": 9000004,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "dw"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

YARA-L #

Panther #

References #

org.cancel_business_invitation

#
Category
org

Description

An invitation for an organization to join an enterprise was revoked

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.cancel_invitation

#
Category
org

Description

An invitation sent to a user to join an organization was revoked.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000038,
  "actor_id": 9000031,
  "token_id": 9000123,
  "created_at": 1780425598220.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "invitation_id": 9000124,
  "oauth_application_id": 9000036,
  "org": "example-org",
  "actor": "user",
  "email": "user",
  "action": "org.cancel_invitation",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000125,
  "user_agent": "Microsoft Azure AD SCIM provisioning",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMA==",
  "token_scopes": "admin:org",
  "invitee_email": "user",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "programmatic_access_type": "OAuth access token",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.clear_custom_invitation_rate_limit

#
Category
org

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.clear_disallowed_two_factor_methods

#
Category
org

Description

Cleared two-factor authentication restrictions for an organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_quality_entity_policy_update

#
Category
org

Description

An organization owner updated the Code Quality entity policy for repositories owned by the organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_ai_findings_disabled

#
Category
org

Description

AI-powered findings for code scanning were disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_ai_findings_enabled

#
Category
org

Description

AI-powered findings for code scanning were enabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_autofix_disabled

#
Category
org

Description

Autofix for code scanning alerts was disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_autofix_enabled

#
Category
org

Description

Autofix for code scanning alerts was enabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_autofix_third_party_tools_disabled

#
Category
org

Description

Autofix for third party tools for code scanning alerts was disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_autofix_third_party_tools_enabled

#
Category
org

Description

Autofix for third party tools for code scanning alerts was enabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_scan_inactive_repos_disabled

#
Category
org

Description

Scanning inactive repositories was disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_scanning_scan_inactive_repos_enabled

#
Category
org

Description

Scanning inactive repositories was enabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_security_metered_usage_lock

#
Category
org

Description

Enablement for Code Security features on new repositories has been locked for this organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.code_security_metered_usage_unlock

#
Category
org

Description

Enablement for Code Security features on new repositories has been unlocked for this organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codeql_disabled

#
Category
org

Description

Code scanning using the default setup was disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codeql_enabled

#
Category
org

Description

Code scanning using the default setup was enabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codespaces_access_updated

#
Category
org

Description

Access to use Codespaces on internal and private repositories was updated for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codespaces_ownership_updated

#
Category
org

Description

Ownership and payment for codespaces was updated for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783902060602,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMjA=",
  "action": "org.codespaces_ownership_updated",
  "actor": "user",
  "actor_id": 9000004,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902060602,
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "owner_type": "Organization",
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.codespaces_team_access_allowed

#
Category
org

Description

A team has been allowed to use Codespaces for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codespaces_team_access_revoked

#
Category
org

Description

A team has been prevented from using Codespaces for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codespaces_trusted_repo_access_granted

#
Category
org

Description

GitHub Codespaces was granted trusted repository access to all other repositories in an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codespaces_trusted_repo_access_revoked

#
Category
org

Description

GitHub Codespaces trusted repository access to all other repositories in an organization was revoked.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codespaces_user_access_allowed

#
Category
org

Description

A user has been allowed to use Codespaces for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.codespaces_user_access_revoked

#
Category
org

Description

A user has been prevented from using Codespaces for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.config.disable_collaborators_only

#
Category
org

Description

The interaction limit for collaborators only for an organization was disabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.config.disable_contributors_only

#
Category
org

Description

The interaction limit for prior contributors only for an organization was disabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.config.disable_sockpuppet_disallowed

#
Category
org

Description

The interaction limit for existing users only for an organization was disabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.config.enable_collaborators_only

#
Category
org

Description

The interaction limit for collaborators only for an organization was enabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.config.enable_contributors_only

#
Category
org

Description

The interaction limit for prior contributors only for an organization was enabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.config.enable_sockpuppet_disallowed

#
Category
org

Description

The interaction limit for existing users only for an organization was enabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.configure_self_hosted_jit_runner

#
Category
org

Description

A new just-in-time GitHub Actions self-hosted runner was configured

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.confirm_business_invitation

#
Category
org

Description

An invitation for an organization to join an enterprise was confirmed.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.connect_usage_metrics_export

#
Category
org

Description

Server statistics were exported for the organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.create

#
Category
org

Description

An organization was created.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783902060511,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMjE=",
  "action": "org.create",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783902060511,
  "operation_type": "create",
  "org": "example-org",
  "org_id": 9000004,
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.create_actions_secret

#
Category
org

Description

A GitHub Actions secret was created for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "actor_id": 9000126,
  "created_at": 1784794558066.0,
  "business_id": 9000005,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "actor": "user",
  "action": "org.create_actions_secret",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000127,
  "user_agent": "PyGithub/Python",
  "visibility": "private",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMQ==",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "programmatic_access_type": "GitHub App server-to-server token"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

References #

org.create_actions_variable

#
Category
org

Description

A GitHub Actions variable was created for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957678898,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMjE=",
  "action": "org.create_actions_variable",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957678898,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "key": "DEPLOY_SYNTHETIC",
  "operation_type": "create",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "BF08:15A139:F7014B1:FBCA81F:6A5508AE",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2",
  "visibility": "all"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.create_integration_secret

#
Category
org

Description

A Codespaces or Dependabot secret was created for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.delete

#
Category
org

Description

An organization was deleted by a user or staff.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.delete_custom_image

#
Category
org

Description

A custom image was deleted for an organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.delete_custom_image_version

#
Category
org

Description

A custom image version was deleted for an organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.disable_member_team_creation_permission

#
Category
org

Description

Team creation was limited to owners.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783913196715,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTE=",
  "action": "org.disable_member_team_creation_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783913196715,
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "request_access_security_header": null,
  "request_id": "C4B6:1E91F2:8424B95:88A20DC:6A545AEB",
  "user": "user",
  "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.7632.6 Safari/537.36",
  "user_id": 9000002
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.disable_oauth_app_restrictions

#
Category
org

Description

Third-party application access restrictions for an organization were disabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

YARA-L #

Panther #

org.disable_reader_discussion_creation_permission

#
Category
org

Description

An organization owner limited discussion creation to users with at least triage permission in an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.disable_saml

#
Category
org

Description

SAML single sign-on was disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

org.disable_source_ip_disclosure

#
Category
org

Description

Display of IP addresses within audit log events for the organization was disabled.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.disable_two_factor_requirement

#
Category
org

Description

A two-factor authentication requirement was disabled for the organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Splunk #

  • GitHub Organizations Disable 2FA Requirement source: The following analytic detects when two-factor authentication (2FA) requirements are disabled in GitHub Organizations. The detection monitors GitHub Organizations audit logs for 2FA requirement changes by tracking actor details,…T1195, T1685
  • GitHub Enterprise Disable 2FA Requirement source: The following analytic detects when two-factor authentication (2FA) requirements are disabled in GitHub Enterprise. The detection monitors GitHub Enterprise audit logs for 2FA requirement changes by tracking actor details, organization…T1195, T1685

Kusto #

  • GitHub Two Factor Auth Disable source medium: Two-factor authentication is a process where a user is prompted during the sign-in process for an additional form of identification, such as to enter a code on their cellphone or to provide a fingerprint scan. Two factor authentication reduces the risk of account takeover. Attacker will want to disable such security tools in order to go undetected.T1562
  • NRT GitHub Two Factor Auth Disable source medium: Two-factor authentication is a process where a user is prompted during the sign-in process for an additional form of identification, such as to enter a code on their cellphone or to provide a fingerprint scan. Two factor authentication reduces the risk of account takeover. Attacker will want to disable such security tools in order to go undetected.T1562

YARA-L #

Panther #

org.display_commenter_full_name_disabled

#
Category
org

Description

An organization owner disabled the display of a commenter's full name in an organization. Members cannot see a comment author's full name.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.display_commenter_full_name_enabled

#
Category
org

Description

An organization owner enabled the display of a commenter's full name in an organization. Members can see a comment author's full name.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.enable_member_team_creation_permission

#
Category
org

Description

Team creation by members was allowed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783913203801,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTA=",
  "action": "org.enable_member_team_creation_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783913203801,
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "request_access_security_header": null,
  "request_id": "C4B6:1E91F2:8426509:88A3AED:6A545AF2",
  "user": "user",
  "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.7632.6 Safari/537.36",
  "user_id": 9000002
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.enable_oauth_app_restrictions

#
Category
org

Description

Third-party application access restrictions for an organization were enabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.enable_reader_discussion_creation_permission

#
Category
org

Description

An organization owner allowed users with read access to create discussions in an organization

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.enable_saml

#
Category
org

Description

SAML single sign-on was enabled for the organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.enable_source_ip_disclosure

#
Category
org

Description

Display of IP addresses within audit log events for the organization was enabled.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.enable_two_factor_requirement

#
Category
org

Description

Two-factor authentication is now required for the organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.integration_manager_added

#
Category
org

Description

An organization owner granted a member access to manage all GitHub Apps owned by an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.integration_manager_removed

#
Category
org

Description

An organization owner removed access to manage all GitHub Apps owned by an organization from an organization member.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.invite_member

#
Category
org

Description

A new user was invited to join an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "user_id": 9000128,
  "actor_id": 9000031,
  "created_at": 1784623416157.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "invitation_id": 9000129,
  "org": "example-org",
  "user": "user",
  "actor": "user",
  "action": "org.invite_member",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000130,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

YARA-L #

  • GitHub Invitation Sent To Non Company Email Domain source high: Detects when an invitation to join a GitHub enterprise or organization is sent to a non-company email address. This rule can be customized to alert you when a GitHub invitation is sent to an unexpected domain i.e. not one of your company's domains used for email.

Panther #

References #

org.invite_to_business

#
Category
org

Description

An organization was invited to join an enterprise.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.members_can_update_protected_branches.disable

#
Category
org

Description

The ability for enterprise members to update protected branches was disabled. Only enterprise owners can update protected branches.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.members_can_update_protected_branches.enable

#
Category
org

Description

The ability for enterprise members to update protected branches was enabled. Members of an organization can update protected branches.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.members_limit_warning

#
Category
org

Description

An organization is approaching its members limit.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.oauth_app_access_approved

#
Category
org

Description

Access to an organization was granted for an OAuth App.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "actor_id": 9000031,
  "created_at": 1781620605925.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "url": "https://example.invalid/orgs/example-org-1/policies/applications/581325/set_state?state=%5BFILTERED%5D",
  "actor": "user",
  "action": "org.oauth_app_access_approved",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000131,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "oauth_application_name": "example-label-142",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.oauth_app_access_blocked

#
Category
org

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.oauth_app_access_denied

#
Category
org

Description

Access was disabled for an OAuth App that was previously approved.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.oauth_app_access_requested

#
Category
org

Description

An organization member requested that an owner grant an OAuth App access to an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "actor_id": 9000132,
  "created_at": 1781542932281.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "url": "https://example.invalid/orgs/example-org-1/policies/applications/581325/request",
  "actor": "user",
  "action": "org.oauth_app_access_requested",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000133,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "oauth_application_name": "example-label-142",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.oauth_app_access_unblocked

#
Category
org

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.rate_limited_invites

#
Category
org

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.recovery_code_failed

#
Category
org

Description

An organization owner failed to sign into a organization with an external identity provider (IdP) using a recovery code.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.recovery_code_used

#
Category
org

Description

An organization owner successfully signed into an organization with an external identity provider (IdP) using a recovery code.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.recovery_codes_downloaded

#
Category
org

Description

An organization owner downloaded the organization's SSO recovery codes.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

org.recovery_codes_generated

#
Category
org

Description

An organization owner generated the organization's SSO recovery codes.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

org.recovery_codes_printed

#
Category
org

Description

An organization owner printed the organization's SSO recovery codes.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

org.recovery_codes_viewed

#
Category
org

Description

An organization owner viewed the organization's SSO recovery codes.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

org.register_self_hosted_runner

#
Category
org

Description

A new self-hosted runner was registered.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

org.remove_actions_secret

#
Category
org

Description

A GitHub Actions secret was removed from an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "actor_id": 9000060,
  "created_at": 1781631925301.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "actor": "user",
  "action": "org.remove_actions_secret",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000134,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.remove_actions_variable

#
Category
org

Description

A GitHub Actions variable was removed from an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957679321,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMTk=",
  "action": "org.remove_actions_variable",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957679321,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "key": "DEPLOY_SYNTHETIC",
  "operation_type": "remove",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "BF08:15A139:F701775:FBCAAEF:6A5508AF",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.remove_billing_manager

#
Category
org

Description

A billing manager was removed from an organization, either manually or due to a two-factor authentication requirement.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.remove_disallowed_two_factor_method

#
Category
org

Description

Removed a two-factor authentication method restriction for an organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.remove_integration_secret

#
Category
org

Description

A Codespaces or Dependabot secret was removed from an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.remove_member

#
Category
org

Description

A member was removed from an organization, either manually or due to a two-factor authentication requirement.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "user_id": 9000135,
  "actor_id": 9000031,
  "token_id": 9000136,
  "created_at": 1781036081010.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "oauth_application_id": 9000036,
  "org": "example-org",
  "user": "user",
  "actor": "user",
  "action": "org.remove_member",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000137,
  "user_agent": "Microsoft Azure AD SCIM provisioning",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMg==",
  "token_scopes": "admin:org",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "external_identity_nameid": "user",
  "programmatic_access_type": "OAuth access token",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

org.remove_outside_collaborator

#
Category
org

Description

An outside collaborator was removed from an organization, either manually or due to a two-factor authentication requirement.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • Github Outside Collaborator Detected source medium: Detects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an owner removes an outside collaborator from an organization or when two-factor authentication is required in an organization and an outside collaborator does not use 2FA or disables 2FA.T1098, T1098.001, T1098.003, T1213, T1213.003

Panther #

org.remove_security_manager

#
Category
org

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957680307,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMTM=",
  "action": "org.remove_security_manager",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957680307,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "remove",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "BF08:15A139:F701E40:FBCB1C0:6A5508B0",
  "team": "example-business-3/example-team-16",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.remove_self_hosted_runner

#
Category
org

Description

A self-hosted runner was removed.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.rename

#
Category
org

Description

An organization was renamed.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.required_workflow_create

#
Category
org

Description

Triggered when a required workflow is created.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.required_workflow_delete

#
Category
org

Description

Triggered when a required workflow is deleted.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.required_workflow_update

#
Category
org

Description

Triggered when a required workflow is updated.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.restore_member

#
Category
org

Description

An organization member was restored.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "user_id": 9000138,
  "actor_id": 9000031,
  "created_at": 1781535368691.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "user": "user",
  "actor": "user",
  "action": "org.restore_member",
  "business": "example-business",
  "request_id": 9000139,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "operation_type": "restore",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.revoke_external_identity

#
Category
org

Description

A member's linked identity was revoked.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.revoke_sso_session

#
Category
org

Description

A member's SAML session was revoked.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.runner_group_created

#
Category
org

Description

A self-hosted runner group was created.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "actor_id": 9000047,
  "created_at": 1783966549140.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "runner_group_id": 9000080,
  "runner_group_allow_public": false,
  "runner_group_restricted_to_workflows": false,
  "org": "example-org",
  "actor": "user",
  "action": "org.runner_group_created",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000140,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "runner_group_name": "example-label-111",
  "external_identity_nameid": "user",
  "external_identity_username": "user",
  "runner_group_selected_workflow_refs": []
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

References #

org.runner_group_removed

#
Category
org

Description

A self-hosted runner group was removed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "actor_id": 9000047,
  "created_at": 1783966636834.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "runner_group_id": 9000141,
  "org": "example-org",
  "actor": "user",
  "action": "org.runner_group_removed",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000142,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

References #

org.runner_group_renamed

#
Category
org

Description

A self-hosted runner group was renamed.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.runner_group_runner_removed

#
Category
org

Description

The REST API was used to remove a self-hosted runner from a group.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.runner_group_runners_added

#
Category
org

Description

A self-hosted runner was added to a group.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.runner_group_runners_updated

#
Category
org

Description

A runner group's list of members was updated.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.runner_group_updated

#
Category
org

Description

The configuration of a self-hosted runner group was changed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "actor_id": 9000047,
  "created_at": 1783966024738.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "runner_group_id": 9000141,
  "runner_group_allow_public": false,
  "runner_group_restricted_to_workflows": false,
  "org": "example-org",
  "actor": "user",
  "action": "org.runner_group_updated",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000143,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "runner_group_name": "example-label-99",
  "external_identity_nameid": "user",
  "network_configuration_id": 9000144,
  "external_identity_username": "user",
  "runner_group_selected_workflow_refs": []
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

References #

org.runner_group_visiblity_updated

#
Category
org

Description

The visibility of a self-hosted runner group was updated via the REST API.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.secret_protection_metered_usage_lock

#
Category
org

Description

Enablement for Secret Protection features on new repositories has been locked for this organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.secret_protection_metered_usage_unlock

#
Category
org

Description

Enablement for Secret Protection features on new repositories has been unlocked for this organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.secret_scanning_custom_pattern_push_protection_disabled

#
Category
org

Description

Push protection for a custom pattern for secret scanning was disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.secret_scanning_custom_pattern_push_protection_enabled

#
Category
org

Description

Push protection for a custom pattern for secret scanning was enabled for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.secret_scanning_push_protection_custom_message_disabled

#
Category
org

Description

The custom message triggered by an attempted push to a push-protected repository was disabled for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957528317,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTg=",
  "action": "org.secret_scanning_push_protection_custom_message_disabled",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957528317,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4C0D89:F98D284:6A550818",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user": "user",
  "user_agent": "python-requests/2.34.2",
  "user_id": 9000002
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.secret_scanning_push_protection_custom_message_enabled

#
Category
org

Description

The custom message triggered by an attempted push to a push-protected repository was enabled for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957527078,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjI=",
  "action": "org.secret_scanning_push_protection_custom_message_enabled",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957527078,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4C05EC:F98CAE2:6A550816",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user": "user",
  "user_agent": "python-requests/2.34.2",
  "user_id": 9000002
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.secret_scanning_push_protection_custom_message_updated

#
Category
org

Description

The custom message triggered by an attempted push to a push-protected repository was updated for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957527108,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjE=",
  "action": "org.secret_scanning_push_protection_custom_message_updated",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957527108,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4C05EC:F98CAE2:6A550816",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user": "user",
  "user_agent": "python-requests/2.34.2",
  "user_id": 9000002
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.secret_scanning_push_protection_disable

#
Category
org

Description

Push protection for secret scanning was disabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.secret_scanning_push_protection_enable

#
Category
org

Description

Push protection for secret scanning was enabled.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.secret_scanning_push_protection_new_repos_disable

#
Category
org

Description

Push protection for secret scanning was disabled for all new repositories in the organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957528836,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTc=",
  "action": "org.secret_scanning_push_protection_new_repos_disable",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957528836,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4C106D:F98D572:6A550818",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user": "user",
  "user_agent": "python-requests/2.34.2",
  "user_id": 9000002
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

References #

org.secret_scanning_push_protection_new_repos_enable

#
Category
org

Description

Push protection for secret scanning was enabled for all new repositories in the organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957526673,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjM=",
  "action": "org.secret_scanning_push_protection_new_repos_enable",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957526673,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4C0365:F98C832:6A550816",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user": "user",
  "user_agent": "python-requests/2.34.2",
  "user_id": 9000002
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.security_center_export_code_scanning_metrics

#
Category
org

Description

A CSV export was requested on the CodeQL pull request alerts page.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.security_center_export_coverage

#
Category
org

Description

A CSV export was requested on the Coverage page.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.security_center_export_overview_dashboard

#
Category
org

Description

A CSV export was requested on the Overview Dashboard page.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.security_center_export_risk

#
Category
org

Description

A CSV export was requested on the Risk page.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.self_hosted_runner_offline

#
Category
org

Description

The runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.self_hosted_runner_online

#
Category
org

Description

The runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.self_hosted_runner_updated

#
Category
org

Description

The runner application was updated. This event is not included in the JSON/CSV export.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_actions_cache_retention_policy

#
Category
org

Description

The cache retention policy for GitHub Actions was set for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_actions_cache_storage_policy

#
Category
org

Description

The cache storage policy for GitHub Actions was set for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_actions_fork_pr_approvals_policy

#
Category
org

Description

The setting for requiring approvals for workflows from public forks was changed for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_actions_private_fork_pr_approvals_policy

#
Category
org

Description

The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_actions_retention_limit

#
Category
org

Description

The retention period for GitHub Actions artifacts and logs in an organization was changed.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_custom_invitation_rate_limit

#
Category
org

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_default_workflow_permissions

#
Category
org

Description

The default permissions granted to the GITHUB_TOKEN when running workflows were changed for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957678642,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMjM=",
  "action": "org.set_default_workflow_permissions",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957678642,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "BF08:15A139:F7012CB:FBCA676:6A5508AE",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • GitHub Workflow Permissions Modified source medium: Detects when the default workflow permissions for the GITHUB_TOKEN are modified at the organization level. GitHub Actions workflows use GITHUB_TOKEN for authentication, and changing these permissions can either expand or restrict what workflows can do by default. Unauthorized modifications could allow attackers to escalate privileges in CI/CD pipelines, potentially leading to supply chain compromise through malicious workflow modifications, unauthorized code deployments, or exfiltration of secrets. This is particularly concerning as it affects all repositories in the organization unless overridden at the repository level.T1195
  • GitHub Org Authentication Method Changed source critical prefix: Detects critical changes to GitHub organization authentication settings including SAML SSO, 2FA requirements, SAML provider configuration, and OAuth restrictions. These foundational security controls protect entire organizations, and unauthorized modifications can enable attackers to bypass identity management, maintain persistence, or prepare for data exfiltration. Legitimate changes are rare and should be well-documented with proper authorization.T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more

References #

org.set_fork_pr_workflows_policy

#
Category
org

Description

The policy for workflows on private repository forks was changed.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.set_workflow_permission_can_approve_pr

#
Category
org

Description

The policy for allowing GitHub Actions to create and approve pull requests was changed for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783902059483,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMjQ=",
  "action": "org.set_workflow_permission_can_approve_pr",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "created_at": 1783902059483,
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "request_access_security_header": null,
  "request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.sso_response

#
Category
org

Description

A SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your organization. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "actor_id": 9000145,
  "created_at": 1785271547568.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "actor": "user",
  "action": "org.sso_response",
  "issuer": "https://example.invalid/00000000-0000-0000-0000-000000000000/",
  "business": "example-business",
  "request_id": 9000146,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "operation_type": "authentication",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.transfer

#
Category
org

Description

An organization was transferred between enterprise accounts.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

org.transfer_outgoing

#
Category
org

Description

An organization was transferred between enterprise accounts.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

YARA-L #

Panther #

org.unarchive

#
Category
org

Description

The organization was unarchived.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.unblock_user

#
Category
org

Description

A user was unblocked from an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783960673259,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMDE=",
  "action": "org.unblock_user",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "blocked_user": "user",
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783960673259,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "operation_type": "remove",
  "org": "example-org",
  "org_id": 9000002,
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "A0A0:34D35:F2CFFDD:F7B8B2F:6A551461",
  "token_id": 9000004,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "dw"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

References #

org.update_actions_secret

#
Category
org

Description

A GitHub Actions secret was updated for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "actor_id": 9000147,
  "created_at": 1782634557072.0,
  "business_id": 9000005,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "actor": "user",
  "action": "org.update_actions_secret",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000148,
  "user_agent": "PyGithub/Python",
  "visibility": "selected",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMw==",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "programmatic_access_type": "GitHub App server-to-server token"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.update_actions_settings

#
Category
org

Description

An organization owner or site administrator updated GitHub Actions policy settings for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "actor_id": 9000149,
  "created_at": 1785269780657.0,
  "business_id": 9000005,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "updated_github_owned_allowed": true,
  "org": "example-org",
  "actor": "user",
  "action": "org.update_actions_settings",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000150,
  "user_agent": "go-github/v88.0.0",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxNA==",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "programmatic_access_type": "GitHub App server-to-server token"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.update_actions_variable

#
Category
org

Description

A GitHub Actions variable was updated for an organization.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "actor_id": 9000084,
  "created_at": 1781613972553.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "actor": "user",
  "action": "org.update_actions_variable",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000151,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.update_custom_images_policy

#
Category
org

Description

The enterprise updated GitHub Actions custom image policy settings for an organization.

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.update_default_repository_permission

#
Category
org

Description

The default repository permission level for organization members was changed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783957523028,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNzA=",
  "action": "org.update_default_repository_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783957523028,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
  "old_permission": "read",
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "permission": "write",
  "programmatic_access_type": "Personal access token (classic)",
  "request_access_security_header": null,
  "request_id": "EA04:7E563:F4BEE40:F98B2CC:6A550812",
  "token_id": 9000006,
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "user_agent": "python-requests/2.34.2"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.update_immutable_releases_settings_policy

#
Category
org

Description

The settings policy for immutable releases was updated for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.update_integration_secret

#
Category
org

Description

A Codespaces or Dependabot secret was updated for an organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.update_member

#
Category
org

Description

A person's role was changed from owner to member or member to owner.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000092,
  "user_id": 9000152,
  "actor_id": 9000153,
  "created_at": 1782229563399.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "user": "user",
  "actor": "user",
  "action": "org.update_member",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "permission": "admin",
  "request_id": 9000154,
  "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "old_permission": "read",
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
github.permission (elastic rule field)eqadmin1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • GitHub Owner Role Granted To User source medium: This rule detects when a member is granted the organization owner role of a GitHub organization. This role provides admin level privileges. Any new owner role should be investigated to determine its validity. Unauthorized owner roles could indicate compromise within your organization and provide unlimited access to data and settings.T1098, T1098.003

Panther #

References #

org.update_member_repository_creation_permission

#
Category
org

Description

The create repository permission for organization members was changed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "actor_id": 9000155,
  "created_at": 1781632041373.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "actor": "user",
  "action": "org.update_member_repository_creation_permission",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "permission": "false",
  "request_id": 9000156,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "all",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.update_member_repository_invitation_permission

#
Category
org

Description

An organization owner changed the policy setting for organization members inviting outside collaborators to repositories.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1783913111740,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjA=",
  "action": "org.update_member_repository_invitation_permission",
  "actor": "user",
  "actor_id": 9000002,
  "actor_is_bot": false,
  "actor_location": {
    "country_code": "XX"
  },
  "business": "example-business",
  "business_id": 9000003,
  "created_at": 1783913111740,
  "operation_type": "modify",
  "org": "example-org",
  "org_id": 9000004,
  "permission": false,
  "request_access_security_header": null,
  "request_id": "C4B6:1E91F2:841037E:888CFBC:6A545A96",
  "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.7632.6 Safari/537.36"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

org.update_new_repository_default_branch_setting

#
Category
org

Description

The name of the default branch was changed for new repositories in the organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.update_repo_self_hosted_runners_policy

#
Category
org

Description

The repository self-hosted runners policy was updated

Documented on GitHub's organization audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

org.update_saml_provider_settings

#
Category
org

Description

An organization's SAML provider settings were updated.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000157,
  "actor_id": 9000031,
  "created_at": 1783416189373.0,
  "business_id": 9000005,
  "actor_is_bot": false,
  "org": "example-org",
  "actor": "user",
  "action": "org.update_saml_provider_settings",
  "issuer": "https://example.invalid/00000000-0000-0000-0000-000000000000/",
  "sso_url": "https://example.invalid/00000000-0000-0000-0000-000000000000/saml2",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000158,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

References #

org.update_terms_of_service

#
Category
org

Description

An organization changed between the Standard Terms of Service and the GitHub Customer Agreement.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #