Org
| action | Description | Sample | Rule |
|---|---|---|---|
| org. | An invitation sent to an organization to join an enterprise was accepted. | N | Y |
| org. | A billing manager was added to an organization. | N | Y |
| org. | An organization prevented access to resources by users with the given two-factor method. | N | Y |
| org. | A user joined an organization. | Y | Y |
| org. | An outside collaborator was added to a repository. | Y | Y |
| org. | Y | Y | |
| org. | GitHub Advanced Security was disabled for new repositories in an organization. | Y | Y |
| org. | GitHub Advanced Security was disabled for all repositories in an organization. | N | Y |
| org. | GitHub Advanced Security was enabled for new repositories in an organization. | Y | Y |
| org. | GitHub Advanced Security was enabled for all repositories in an organization. | N | Y |
| org. | An enterprise owner updated the GitHub Advanced Security access policy for repositories owned by the organization. | N | Y |
| org. | An enterprise owner prevented GitHub Advanced Security features from being enabled for repositories owned by the organization. | N | Y |
| org. | An enterprise owner allowed GitHub Advanced Security features to be enabled for repositories owned by the organization. | N | Y |
| org. | Third-party application access for outside collaborators was disabled for the organization. | N | Y |
| org. | Third-party application access for outside collaborators was enabled for the organization. | N | Y |
| org. | The organization was archived. | N | Y |
| org. | An export of the organization audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query. | Y | Y |
| org. | An export of the organization's Git events was created. | N | Y |
| org. | N | Y | |
| org. | An organization owner blocked a user from accessing the organization's repositories. | Y | Y |
| org. | An invitation for an organization to join an enterprise was revoked | N | Y |
| org. | An invitation sent to a user to join an organization was revoked. | Y | Y |
| org. | N | Y | |
| org. | Cleared two-factor authentication restrictions for an organization. | N | Y |
| org. | An organization owner updated the Code Quality entity policy for repositories owned by the organization. | N | Y |
| org. | AI-powered findings for code scanning were disabled for an organization. | N | Y |
| org. | AI-powered findings for code scanning were enabled for an organization. | N | Y |
| org. | Autofix for code scanning alerts was disabled for an organization. | N | Y |
| org. | Autofix for code scanning alerts was enabled for an organization. | N | Y |
| org. | Autofix for third party tools for code scanning alerts was disabled for an organization. | N | Y |
| org. | Autofix for third party tools for code scanning alerts was enabled for an organization. | N | Y |
| org. | Scanning inactive repositories was disabled for an organization. | N | Y |
| org. | Scanning inactive repositories was enabled for an organization. | N | Y |
| org. | Enablement for Code Security features on new repositories has been locked for this organization. | N | Y |
| org. | Enablement for Code Security features on new repositories has been unlocked for this organization. | N | Y |
| org. | Code scanning using the default setup was disabled for an organization. | N | Y |
| org. | Code scanning using the default setup was enabled for an organization. | N | Y |
| org. | Access to use Codespaces on internal and private repositories was updated for an organization. | N | Y |
| org. | Ownership and payment for codespaces was updated for an organization. | Y | Y |
| org. | A team has been allowed to use Codespaces for an organization. | N | Y |
| org. | A team has been prevented from using Codespaces for an organization. | N | Y |
| org. | GitHub Codespaces was granted trusted repository access to all other repositories in an organization. | N | Y |
| org. | GitHub Codespaces trusted repository access to all other repositories in an organization was revoked. | N | Y |
| org. | A user has been allowed to use Codespaces for an organization. | N | Y |
| org. | A user has been prevented from using Codespaces for an organization. | N | Y |
| org. | The interaction limit for collaborators only for an organization was disabled. | N | Y |
| org. | The interaction limit for prior contributors only for an organization was disabled. | N | Y |
| org. | The interaction limit for existing users only for an organization was disabled. | N | Y |
| org. | The interaction limit for collaborators only for an organization was enabled. | N | Y |
| org. | The interaction limit for prior contributors only for an organization was enabled. | N | Y |
| org. | The interaction limit for existing users only for an organization was enabled. | N | Y |
| org. | A new just-in-time GitHub Actions self-hosted runner was configured | N | Y |
| org. | An invitation for an organization to join an enterprise was confirmed. | N | Y |
| org. | Server statistics were exported for the organization. | N | Y |
| org. | An organization was created. | Y | Y |
| org. | A GitHub Actions secret was created for an organization. | Y | Y |
| org. | A GitHub Actions variable was created for an organization. | Y | Y |
| org. | A Codespaces or Dependabot secret was created for an organization. | N | Y |
| org. | An organization was deleted by a user or staff. | N | Y |
| org. | A custom image was deleted for an organization. | N | Y |
| org. | A custom image version was deleted for an organization. | N | Y |
| org. | Team creation was limited to owners. | Y | Y |
| org. | Third-party application access restrictions for an organization were disabled. | N | Y |
| org. | An organization owner limited discussion creation to users with at least triage permission in an organization. | N | Y |
| org. | SAML single sign-on was disabled for an organization. | N | Y |
| org. | Display of IP addresses within audit log events for the organization was disabled. | N | Y |
| org. | A two-factor authentication requirement was disabled for the organization. | N | Y |
| org. | An organization owner disabled the display of a commenter's full name in an organization. Members cannot see a comment author's full name. | N | Y |
| org. | An organization owner enabled the display of a commenter's full name in an organization. Members can see a comment author's full name. | N | Y |
| org. | Team creation by members was allowed. | Y | Y |
| org. | Third-party application access restrictions for an organization were enabled. | N | Y |
| org. | An organization owner allowed users with read access to create discussions in an organization | N | Y |
| org. | SAML single sign-on was enabled for the organization. | N | Y |
| org. | Display of IP addresses within audit log events for the organization was enabled. | N | Y |
| org. | Two-factor authentication is now required for the organization. | N | Y |
| org. | An organization owner granted a member access to manage all GitHub Apps owned by an organization. | N | Y |
| org. | An organization owner removed access to manage all GitHub Apps owned by an organization from an organization member. | N | Y |
| org. | A new user was invited to join an organization. | Y | Y |
| org. | An organization was invited to join an enterprise. | N | Y |
| org. | The ability for enterprise members to update protected branches was disabled. Only enterprise owners can update protected branches. | N | Y |
| org. | The ability for enterprise members to update protected branches was enabled. Members of an organization can update protected branches. | N | Y |
| org. | An organization is approaching its members limit. | N | Y |
| org. | Access to an organization was granted for an OAuth App. | Y | Y |
| org. | N | Y | |
| org. | Access was disabled for an OAuth App that was previously approved. | N | Y |
| org. | An organization member requested that an owner grant an OAuth App access to an organization. | Y | Y |
| org. | N | Y | |
| org. | N | Y | |
| org. | An organization owner failed to sign into a organization with an external identity provider (IdP) using a recovery code. | N | Y |
| org. | An organization owner successfully signed into an organization with an external identity provider (IdP) using a recovery code. | N | Y |
| org. | An organization owner downloaded the organization's SSO recovery codes. | N | Y |
| org. | An organization owner generated the organization's SSO recovery codes. | N | Y |
| org. | An organization owner printed the organization's SSO recovery codes. | N | Y |
| org. | An organization owner viewed the organization's SSO recovery codes. | N | Y |
| org. | A new self-hosted runner was registered. | N | Y |
| org. | A GitHub Actions secret was removed from an organization. | Y | Y |
| org. | A GitHub Actions variable was removed from an organization. | Y | Y |
| org. | A billing manager was removed from an organization, either manually or due to a two-factor authentication requirement. | N | Y |
| org. | Removed a two-factor authentication method restriction for an organization. | N | Y |
| org. | A Codespaces or Dependabot secret was removed from an organization. | N | Y |
| org. | A member was removed from an organization, either manually or due to a two-factor authentication requirement. | Y | Y |
| org. | An outside collaborator was removed from an organization, either manually or due to a two-factor authentication requirement. | N | Y |
| org. | Y | Y | |
| org. | A self-hosted runner was removed. | N | Y |
| org. | An organization was renamed. | N | Y |
| org. | Triggered when a required workflow is created. | N | Y |
| org. | Triggered when a required workflow is deleted. | N | Y |
| org. | Triggered when a required workflow is updated. | N | Y |
| org. | An organization member was restored. | Y | Y |
| org. | A member's linked identity was revoked. | N | Y |
| org. | A member's SAML session was revoked. | N | Y |
| org. | A self-hosted runner group was created. | Y | Y |
| org. | A self-hosted runner group was removed. | Y | Y |
| org. | A self-hosted runner group was renamed. | N | Y |
| org. | The REST API was used to remove a self-hosted runner from a group. | N | Y |
| org. | A self-hosted runner was added to a group. | N | Y |
| org. | A runner group's list of members was updated. | N | Y |
| org. | The configuration of a self-hosted runner group was changed. | Y | Y |
| org. | The visibility of a self-hosted runner group was updated via the REST API. | N | Y |
| org. | Enablement for Secret Protection features on new repositories has been locked for this organization. | N | Y |
| org. | Enablement for Secret Protection features on new repositories has been unlocked for this organization. | N | Y |
| org. | Push protection for a custom pattern for secret scanning was disabled for an organization. | N | Y |
| org. | Push protection for a custom pattern for secret scanning was enabled for an organization. | N | Y |
| org. | The custom message triggered by an attempted push to a push-protected repository was disabled for an organization. | Y | Y |
| org. | The custom message triggered by an attempted push to a push-protected repository was enabled for an organization. | Y | Y |
| org. | The custom message triggered by an attempted push to a push-protected repository was updated for an organization. | Y | Y |
| org. | Push protection for secret scanning was disabled. | N | Y |
| org. | Push protection for secret scanning was enabled. | N | Y |
| org. | Push protection for secret scanning was disabled for all new repositories in the organization. | Y | Y |
| org. | Push protection for secret scanning was enabled for all new repositories in the organization. | Y | Y |
| org. | A CSV export was requested on the CodeQL pull request alerts page. | N | Y |
| org. | A CSV export was requested on the Coverage page. | N | Y |
| org. | A CSV export was requested on the Overview Dashboard page. | N | Y |
| org. | A CSV export was requested on the Risk page. | N | Y |
| org. | The runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports. | N | Y |
| org. | The runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports. | N | Y |
| org. | The runner application was updated. This event is not included in the JSON/CSV export. | N | Y |
| org. | The cache retention policy for GitHub Actions was set for an organization. | N | Y |
| org. | The cache storage policy for GitHub Actions was set for an organization. | N | Y |
| org. | The setting for requiring approvals for workflows from public forks was changed for an organization. | N | Y |
| org. | The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an organization. | N | Y |
| org. | The retention period for GitHub Actions artifacts and logs in an organization was changed. | N | Y |
| org. | N | Y | |
| org. | The default permissions granted to the GITHUB_TOKEN when running workflows were changed for an organization. | Y | Y |
| org. | The policy for workflows on private repository forks was changed. | N | Y |
| org. | The policy for allowing GitHub Actions to create and approve pull requests was changed for an organization. | Y | Y |
| org. | A SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your organization. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports. | Y | Y |
| org. | An organization was transferred between enterprise accounts. | N | Y |
| org. | An organization was transferred between enterprise accounts. | N | Y |
| org. | The organization was unarchived. | N | Y |
| org. | A user was unblocked from an organization. | Y | Y |
| org. | A GitHub Actions secret was updated for an organization. | Y | Y |
| org. | An organization owner or site administrator updated GitHub Actions policy settings for an organization. | Y | Y |
| org. | A GitHub Actions variable was updated for an organization. | Y | Y |
| org. | The enterprise updated GitHub Actions custom image policy settings for an organization. | N | Y |
| org. | The default repository permission level for organization members was changed. | Y | Y |
| org. | The settings policy for immutable releases was updated for an organization. | N | Y |
| org. | A Codespaces or Dependabot secret was updated for an organization. | N | Y |
| org. | A person's role was changed from owner to member or member to owner. | Y | Y |
| org. | The create repository permission for organization members was changed. | Y | Y |
| org. | An organization owner changed the policy setting for organization members inviting outside collaborators to repositories. | Y | Y |
| org. | The name of the default branch was changed for new repositories in the organization. | N | Y |
| org. | The repository self-hosted runners policy was updated | N | Y |
| org. | An organization's SAML provider settings were updated. | Y | Y |
| org. | An organization changed between the Standard Terms of Service and the GitHub Customer Agreement. | N | Y |
org.accept_business_invitation
#Description
An invitation sent to an organization to join an enterprise was accepted.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, org.advanced_security_disabled_for_new_repos, and 158 more
org.add_billing_manager
#Description
A billing manager was added to an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, org.advanced_security_disabled_for_new_repos, and 158 more
org.add_disallowed_two_factor_method
#Description
An organization prevented access to resources by users with the given two-factor method.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_member, org.add_outside_collaborator, org.add_security_manager, org.advanced_security_disabled_for_new_repos, and 158 more
org.add_member
#Description
A user joined an organization.
Documented on GitHub's enterprise audit log reference. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000097,
"user_id": 9000115,
"actor_id": 9000031,
"created_at": 1781023684187.0,
"business_id": 9000005,
"actor_is_bot": false,
"invitation_id": 9000116,
"org": "example-org",
"user": "user",
"actor": "user",
"action": "org.add_member",
"business": "example-business",
"permission": "read",
"request_id": 9000117,
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36 Edg/ip-redacted",
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Common Indicators #
Field Kind Value Rules Vendors github.permission (elastic rule field)eq admin1 rule elastic Detection Rules #
Sigma #
T1136, T1136.003↳ also matches org.invite_member Elastic #
T1098, T1098.003, T1136, T1136.003T1098, T1098.001, T1098.003Kusto #
T1078Panther #
T1195↳ also matches org.remove_member T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_outside_collaborator, org.add_security_manager, org.advanced_security_disabled_for_new_repos, and 158 more References #
org.add_outside_collaborator
#Description
An outside collaborator was added to a repository.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000092,
"repo_id": 9000118,
"actor_id": 9000119,
"created_at": 1782224607048.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "org.add_outside_collaborator",
"invitee": "user",
"inviter": "user",
"actor_ip": "ip-redacted",
"business": "example-business",
"permission": "read",
"request_id": 9000120,
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_security_manager, org.advanced_security_disabled_for_new_repos, and 158 more References #
org.add_security_manager
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957680008,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMTU=",
"action": "org.add_security_manager",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957680008,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "create",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "BF08:15A139:F701C69:FBCAFFB:6A5508AF",
"team": "example-business-3/example-team-16",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.advanced_security_disabled_for_new_repos, and 158 more References #
org.advanced_security_disabled_for_new_repos
#Description
GitHub Advanced Security was disabled for new repositories in an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957527906,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTk=",
"action": "org.advanced_security_disabled_for_new_repos",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957527906,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4C0B35:F98D04F:6A550817",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
Detection Rules #
Sigma #
T1556↳ also matches org.advanced_security_disabled_on_all_repos, org.advanced_security_policy_selected_member_disabled, org.disable_oauth_app_restrictions, org.disable_two_factor_requirement Panther #
T1562↳ also matches org.advanced_security_disabled_on_all_repos, org.advanced_security_policy_selected_member_disabled T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.advanced_security_disabled_on_all_repos
#Description
GitHub Advanced Security was disabled for all repositories in an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1556↳ also matches org.advanced_security_disabled_for_new_repos, org.advanced_security_policy_selected_member_disabled, org.disable_oauth_app_restrictions, org.disable_two_factor_requirement Panther #
T1562↳ also matches org.advanced_security_disabled_for_new_repos, org.advanced_security_policy_selected_member_disabled T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.advanced_security_enabled_for_new_repos
#Description
GitHub Advanced Security was enabled for new repositories in an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957527504,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjA=",
"action": "org.advanced_security_enabled_for_new_repos",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957527504,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4C08AF:F98CD9A:6A550817",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.advanced_security_enabled_on_all_repos
#Description
GitHub Advanced Security was enabled for all repositories in an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.advanced_security_entity_policy_update
#Description
An enterprise owner updated the GitHub Advanced Security access policy for repositories owned by the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.advanced_security_policy_selected_member_disabled
#Description
An enterprise owner prevented GitHub Advanced Security features from being enabled for repositories owned by the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1556↳ also matches org.advanced_security_disabled_for_new_repos, org.advanced_security_disabled_on_all_repos, org.disable_oauth_app_restrictions, org.disable_two_factor_requirement Panther #
T1562↳ also matches org.advanced_security_disabled_for_new_repos, org.advanced_security_disabled_on_all_repos T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.advanced_security_policy_selected_member_enabled
#Description
An enterprise owner allowed GitHub Advanced Security features to be enabled for repositories owned by the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.allow_third_party_access_requests_from_outside_collaborators_disabled
#Description
Third-party application access for outside collaborators was disabled for the organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.allow_third_party_access_requests_from_outside_collaborators_enabled
#Description
Third-party application access for outside collaborators was enabled for the organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.archive
#Description
The organization was archived.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.audit_log_export
#Description
An export of the organization audit log was created. If the export included a query, the log will list the query used and the number of audit log entries matching that query.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"actor_id": 9000121,
"created_at": 1782855852272.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"actor": "user",
"action": "org.audit_log_export",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000122,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"query_phrase": "actor:user ",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.audit_log_git_event_export
#Description
An export of the organization's Git events was created.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.billing_signup_error
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.block_user
#Description
An organization owner blocked a user from accessing the organization's repositories.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783960672700,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMDI=",
"action": "org.block_user",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"blocked_user": "user",
"business": "example-business",
"business_id": 9000003,
"created_at": 1783960672700,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "create",
"org": "example-org",
"org_id": 9000002,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "9562:3D1F96:F8FAFB2:FDD48B2:6A551460",
"token_id": 9000004,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "dw"
}
Detection Rules #
Elastic #
T1531Kusto #
T1078YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.cancel_business_invitation
#Description
An invitation for an organization to join an enterprise was revoked
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.cancel_invitation
#Description
An invitation sent to a user to join an organization was revoked.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000038,
"actor_id": 9000031,
"token_id": 9000123,
"created_at": 1780425598220.0,
"business_id": 9000005,
"actor_is_bot": false,
"invitation_id": 9000124,
"oauth_application_id": 9000036,
"org": "example-org",
"actor": "user",
"email": "user",
"action": "org.cancel_invitation",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000125,
"user_agent": "Microsoft Azure AD SCIM provisioning",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMA==",
"token_scopes": "admin:org",
"invitee_email": "user",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"programmatic_access_type": "OAuth access token",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.clear_custom_invitation_rate_limit
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.clear_disallowed_two_factor_methods
#Description
Cleared two-factor authentication restrictions for an organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_quality_entity_policy_update
#Description
An organization owner updated the Code Quality entity policy for repositories owned by the organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_ai_findings_disabled
#Description
AI-powered findings for code scanning were disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_ai_findings_enabled
#Description
AI-powered findings for code scanning were enabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_autofix_disabled
#Description
Autofix for code scanning alerts was disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_autofix_enabled
#Description
Autofix for code scanning alerts was enabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_autofix_third_party_tools_disabled
#Description
Autofix for third party tools for code scanning alerts was disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_autofix_third_party_tools_enabled
#Description
Autofix for third party tools for code scanning alerts was enabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_scan_inactive_repos_disabled
#Description
Scanning inactive repositories was disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_scanning_scan_inactive_repos_enabled
#Description
Scanning inactive repositories was enabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_security_metered_usage_lock
#Description
Enablement for Code Security features on new repositories has been locked for this organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.code_security_metered_usage_unlock
#Description
Enablement for Code Security features on new repositories has been unlocked for this organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codeql_disabled
#Description
Code scanning using the default setup was disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codeql_enabled
#Description
Code scanning using the default setup was enabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codespaces_access_updated
#Description
Access to use Codespaces on internal and private repositories was updated for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codespaces_ownership_updated
#Description
Ownership and payment for codespaces was updated for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783902060602,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMjA=",
"action": "org.codespaces_ownership_updated",
"actor": "user",
"actor_id": 9000004,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902060602,
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"owner_type": "Organization",
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.codespaces_team_access_allowed
#Description
A team has been allowed to use Codespaces for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codespaces_team_access_revoked
#Description
A team has been prevented from using Codespaces for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codespaces_trusted_repo_access_granted
#Description
GitHub Codespaces was granted trusted repository access to all other repositories in an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codespaces_trusted_repo_access_revoked
#Description
GitHub Codespaces trusted repository access to all other repositories in an organization was revoked.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codespaces_user_access_allowed
#Description
A user has been allowed to use Codespaces for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.codespaces_user_access_revoked
#Description
A user has been prevented from using Codespaces for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.config.disable_collaborators_only
#Description
The interaction limit for collaborators only for an organization was disabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.config.disable_contributors_only
#Description
The interaction limit for prior contributors only for an organization was disabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.config.disable_sockpuppet_disallowed
#Description
The interaction limit for existing users only for an organization was disabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.config.enable_collaborators_only
#Description
The interaction limit for collaborators only for an organization was enabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.config.enable_contributors_only
#Description
The interaction limit for prior contributors only for an organization was enabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.config.enable_sockpuppet_disallowed
#Description
The interaction limit for existing users only for an organization was enabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.configure_self_hosted_jit_runner
#Description
A new just-in-time GitHub Actions self-hosted runner was configured
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.confirm_business_invitation
#Description
An invitation for an organization to join an enterprise was confirmed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.connect_usage_metrics_export
#Description
Server statistics were exported for the organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.create
#Description
An organization was created.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783902060511,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMjE=",
"action": "org.create",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783902060511,
"operation_type": "create",
"org": "example-org",
"org_id": 9000004,
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.create_actions_secret
#Description
A GitHub Actions secret was created for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"actor_id": 9000126,
"created_at": 1784794558066.0,
"business_id": 9000005,
"actor_is_bot": true,
"actor_is_agent": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"actor": "user",
"action": "org.create_actions_secret",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000127,
"user_agent": "PyGithub/Python",
"visibility": "private",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMQ==",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"programmatic_access_type": "GitHub App server-to-server token"
}
Detection Rules #
Sigma #
T1078, T1078.004Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.create_actions_variable
#Description
A GitHub Actions variable was created for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957678898,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMjE=",
"action": "org.create_actions_variable",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957678898,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"key": "DEPLOY_SYNTHETIC",
"operation_type": "create",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "BF08:15A139:F7014B1:FBCA81F:6A5508AE",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2",
"visibility": "all"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.create_integration_secret
#Description
A Codespaces or Dependabot secret was created for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.delete
#Description
An organization was deleted by a user or staff.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.delete_custom_image
#Description
A custom image was deleted for an organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.delete_custom_image_version
#Description
A custom image version was deleted for an organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.disable_member_team_creation_permission
#Description
Team creation was limited to owners.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783913196715,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTE=",
"action": "org.disable_member_team_creation_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783913196715,
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"request_access_security_header": null,
"request_id": "C4B6:1E91F2:8424B95:88A20DC:6A545AEB",
"user": "user",
"user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.7632.6 Safari/537.36",
"user_id": 9000002
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.disable_oauth_app_restrictions
#Description
Third-party application access restrictions for an organization were disabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1556↳ also matches org.advanced_security_disabled_for_new_repos, org.advanced_security_disabled_on_all_repos, org.advanced_security_policy_selected_member_disabled, org.disable_two_factor_requirement YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.disable_reader_discussion_creation_permission
#Description
An organization owner limited discussion creation to users with at least triage permission in an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.disable_saml
#Description
SAML single sign-on was disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
T1562↳ also matches org.update_saml_provider_settings Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.disable_source_ip_disclosure
#Description
Display of IP addresses within audit log events for the organization was disabled.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.disable_two_factor_requirement
#Description
A two-factor authentication requirement was disabled for the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1556↳ also matches org.advanced_security_disabled_for_new_repos, org.advanced_security_disabled_on_all_repos, org.advanced_security_policy_selected_member_disabled, org.disable_oauth_app_restrictions Splunk #
T1195, T1685T1195, T1685Kusto #
T1562T1562YARA-L #
T1562Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.display_commenter_full_name_disabled
#Description
An organization owner disabled the display of a commenter's full name in an organization. Members cannot see a comment author's full name.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.display_commenter_full_name_enabled
#Description
An organization owner enabled the display of a commenter's full name in an organization. Members can see a comment author's full name.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.enable_member_team_creation_permission
#Description
Team creation by members was allowed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783913203801,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTA=",
"action": "org.enable_member_team_creation_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783913203801,
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"request_access_security_header": null,
"request_id": "C4B6:1E91F2:8426509:88A3AED:6A545AF2",
"user": "user",
"user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.7632.6 Safari/537.36",
"user_id": 9000002
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.enable_oauth_app_restrictions
#Description
Third-party application access restrictions for an organization were enabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.enable_reader_discussion_creation_permission
#Description
An organization owner allowed users with read access to create discussions in an organization
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.enable_saml
#Description
SAML single sign-on was enabled for the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.enable_source_ip_disclosure
#Description
Display of IP addresses within audit log events for the organization was enabled.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.enable_two_factor_requirement
#Description
Two-factor authentication is now required for the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.integration_manager_added
#Description
An organization owner granted a member access to manage all GitHub Apps owned by an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.integration_manager_removed
#Description
An organization owner removed access to manage all GitHub Apps owned by an organization from an organization member.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.invite_member
#Description
A new user was invited to join an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"user_id": 9000128,
"actor_id": 9000031,
"created_at": 1784623416157.0,
"business_id": 9000005,
"actor_is_bot": false,
"invitation_id": 9000129,
"org": "example-org",
"user": "user",
"actor": "user",
"action": "org.invite_member",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000130,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Sigma #
T1136, T1136.003↳ also matches org.add_member Kusto #
T1078YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.invite_to_business
#Description
An organization was invited to join an enterprise.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.members_can_update_protected_branches.disable
#Description
The ability for enterprise members to update protected branches was disabled. Only enterprise owners can update protected branches.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.members_can_update_protected_branches.enable
#Description
The ability for enterprise members to update protected branches was enabled. Members of an organization can update protected branches.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.members_limit_warning
#Description
An organization is approaching its members limit.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.oauth_app_access_approved
#Description
Access to an organization was granted for an OAuth App.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"actor_id": 9000031,
"created_at": 1781620605925.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"url": "https://example.invalid/orgs/example-org-1/policies/applications/581325/set_state?state=%5BFILTERED%5D",
"actor": "user",
"action": "org.oauth_app_access_approved",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000131,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"oauth_application_name": "example-label-142",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.oauth_app_access_blocked
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.oauth_app_access_denied
#Description
Access was disabled for an OAuth App that was previously approved.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.oauth_app_access_requested
#Description
An organization member requested that an owner grant an OAuth App access to an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"actor_id": 9000132,
"created_at": 1781542932281.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"url": "https://example.invalid/orgs/example-org-1/policies/applications/581325/request",
"actor": "user",
"action": "org.oauth_app_access_requested",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000133,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"oauth_application_name": "example-label-142",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.oauth_app_access_unblocked
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.rate_limited_invites
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.recovery_code_failed
#Description
An organization owner failed to sign into a organization with an external identity provider (IdP) using a recovery code.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.recovery_code_used
#Description
An organization owner successfully signed into an organization with an external identity provider (IdP) using a recovery code.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.recovery_codes_downloaded
#Description
An organization owner downloaded the organization's SSO recovery codes.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.recovery_codes_generated
#Description
An organization owner generated the organization's SSO recovery codes.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.recovery_codes_printed
#Description
An organization owner printed the organization's SSO recovery codes.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.recovery_codes_viewed
#Description
An organization owner viewed the organization's SSO recovery codes.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.register_self_hosted_runner
#Description
A new self-hosted runner was registered.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Elastic #
T1195, T1195.001, T1195.002Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.remove_actions_secret
#Description
A GitHub Actions secret was removed from an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"actor_id": 9000060,
"created_at": 1781631925301.0,
"business_id": 9000005,
"actor_is_bot": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"actor": "user",
"action": "org.remove_actions_secret",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000134,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.remove_actions_variable
#Description
A GitHub Actions variable was removed from an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957679321,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMTk=",
"action": "org.remove_actions_variable",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957679321,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"key": "DEPLOY_SYNTHETIC",
"operation_type": "remove",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "BF08:15A139:F701775:FBCAAEF:6A5508AF",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.remove_billing_manager
#Description
A billing manager was removed from an organization, either manually or due to a two-factor authentication requirement.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.remove_disallowed_two_factor_method
#Description
Removed a two-factor authentication method restriction for an organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.remove_integration_secret
#Description
A Codespaces or Dependabot secret was removed from an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.remove_member
#Description
A member was removed from an organization, either manually or due to a two-factor authentication requirement.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"user_id": 9000135,
"actor_id": 9000031,
"token_id": 9000136,
"created_at": 1781036081010.0,
"business_id": 9000005,
"actor_is_bot": false,
"oauth_application_id": 9000036,
"org": "example-org",
"user": "user",
"actor": "user",
"action": "org.remove_member",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000137,
"user_agent": "Microsoft Azure AD SCIM provisioning",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMg==",
"token_scopes": "admin:org",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"external_identity_nameid": "user",
"programmatic_access_type": "OAuth access token",
"external_identity_username": "user"
}
Detection Rules #
Elastic #
T1531Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more T1195↳ also matches org.add_member References #
org.remove_outside_collaborator
#Description
An outside collaborator was removed from an organization, either manually or due to a two-factor authentication requirement.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1098, T1098.001, T1098.003, T1213, T1213.003Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.remove_security_manager
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957680307,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMTM=",
"action": "org.remove_security_manager",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957680307,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "remove",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "BF08:15A139:F701E40:FBCB1C0:6A5508B0",
"team": "example-business-3/example-team-16",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.remove_self_hosted_runner
#Description
A self-hosted runner was removed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches org.runner_group_created, org.runner_group_removed, org.runner_group_runner_removed, org.runner_group_runners_added, org.runner_group_runners_updated, org.runner_group_updated Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.rename
#Description
An organization was renamed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.required_workflow_create
#Description
Triggered when a required workflow is created.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.required_workflow_delete
#Description
Triggered when a required workflow is deleted.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.required_workflow_update
#Description
Triggered when a required workflow is updated.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.restore_member
#Description
An organization member was restored.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"user_id": 9000138,
"actor_id": 9000031,
"created_at": 1781535368691.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"user": "user",
"actor": "user",
"action": "org.restore_member",
"business": "example-business",
"request_id": 9000139,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"operation_type": "restore",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.revoke_external_identity
#Description
A member's linked identity was revoked.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.revoke_sso_session
#Description
A member's SAML session was revoked.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.runner_group_created
#Description
A self-hosted runner group was created.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"actor_id": 9000047,
"created_at": 1783966549140.0,
"business_id": 9000005,
"actor_is_bot": false,
"runner_group_id": 9000080,
"runner_group_allow_public": false,
"runner_group_restricted_to_workflows": false,
"org": "example-org",
"actor": "user",
"action": "org.runner_group_created",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000140,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"runner_group_name": "example-label-111",
"external_identity_nameid": "user",
"external_identity_username": "user",
"runner_group_selected_workflow_refs": []
}
Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches org.remove_self_hosted_runner, org.runner_group_removed, org.runner_group_runner_removed, org.runner_group_runners_added, org.runner_group_runners_updated, org.runner_group_updated Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.runner_group_removed
#Description
A self-hosted runner group was removed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"actor_id": 9000047,
"created_at": 1783966636834.0,
"business_id": 9000005,
"actor_is_bot": false,
"runner_group_id": 9000141,
"org": "example-org",
"actor": "user",
"action": "org.runner_group_removed",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000142,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches org.remove_self_hosted_runner, org.runner_group_created, org.runner_group_runner_removed, org.runner_group_runners_added, org.runner_group_runners_updated, org.runner_group_updated Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.runner_group_renamed
#Description
A self-hosted runner group was renamed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.runner_group_runner_removed
#Description
The REST API was used to remove a self-hosted runner from a group.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches org.remove_self_hosted_runner, org.runner_group_created, org.runner_group_removed, org.runner_group_runners_added, org.runner_group_runners_updated, org.runner_group_updated Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.runner_group_runners_added
#Description
A self-hosted runner was added to a group.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches org.remove_self_hosted_runner, org.runner_group_created, org.runner_group_removed, org.runner_group_runner_removed, org.runner_group_runners_updated, org.runner_group_updated Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.runner_group_runners_updated
#Description
A runner group's list of members was updated.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches org.remove_self_hosted_runner, org.runner_group_created, org.runner_group_removed, org.runner_group_runner_removed, org.runner_group_runners_added, org.runner_group_updated Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.runner_group_updated
#Description
The configuration of a self-hosted runner group was changed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"actor_id": 9000047,
"created_at": 1783966024738.0,
"business_id": 9000005,
"actor_is_bot": false,
"runner_group_id": 9000141,
"runner_group_allow_public": false,
"runner_group_restricted_to_workflows": false,
"org": "example-org",
"actor": "user",
"action": "org.runner_group_updated",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000143,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"runner_group_name": "example-label-99",
"external_identity_nameid": "user",
"network_configuration_id": 9000144,
"external_identity_username": "user",
"runner_group_selected_workflow_refs": []
}
Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches org.remove_self_hosted_runner, org.runner_group_created, org.runner_group_removed, org.runner_group_runner_removed, org.runner_group_runners_added, org.runner_group_runners_updated Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.runner_group_visiblity_updated
#Description
The visibility of a self-hosted runner group was updated via the REST API.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.secret_protection_metered_usage_lock
#Description
Enablement for Secret Protection features on new repositories has been locked for this organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.secret_protection_metered_usage_unlock
#Description
Enablement for Secret Protection features on new repositories has been unlocked for this organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.secret_scanning_custom_pattern_push_protection_disabled
#Description
Push protection for a custom pattern for secret scanning was disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1685↳ also matches org.secret_scanning_push_protection_disable, org.secret_scanning_push_protection_new_repos_disable Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.secret_scanning_custom_pattern_push_protection_enabled
#Description
Push protection for a custom pattern for secret scanning was enabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.secret_scanning_push_protection_custom_message_disabled
#Description
The custom message triggered by an attempted push to a push-protected repository was disabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957528317,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTg=",
"action": "org.secret_scanning_push_protection_custom_message_disabled",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957528317,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4C0D89:F98D284:6A550818",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user": "user",
"user_agent": "python-requests/2.34.2",
"user_id": 9000002
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.secret_scanning_push_protection_custom_message_enabled
#Description
The custom message triggered by an attempted push to a push-protected repository was enabled for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957527078,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjI=",
"action": "org.secret_scanning_push_protection_custom_message_enabled",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957527078,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4C05EC:F98CAE2:6A550816",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user": "user",
"user_agent": "python-requests/2.34.2",
"user_id": 9000002
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.secret_scanning_push_protection_custom_message_updated
#Description
The custom message triggered by an attempted push to a push-protected repository was updated for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957527108,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjE=",
"action": "org.secret_scanning_push_protection_custom_message_updated",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957527108,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4C05EC:F98CAE2:6A550816",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user": "user",
"user_agent": "python-requests/2.34.2",
"user_id": 9000002
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.secret_scanning_push_protection_disable
#Description
Push protection for secret scanning was disabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1685↳ also matches org.secret_scanning_custom_pattern_push_protection_disabled, org.secret_scanning_push_protection_new_repos_disable Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.secret_scanning_push_protection_enable
#Description
Push protection for secret scanning was enabled.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.secret_scanning_push_protection_new_repos_disable
#Description
Push protection for secret scanning was disabled for all new repositories in the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957528836,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNTc=",
"action": "org.secret_scanning_push_protection_new_repos_disable",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957528836,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4C106D:F98D572:6A550818",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user": "user",
"user_agent": "python-requests/2.34.2",
"user_id": 9000002
}
Detection Rules #
Sigma #
T1685↳ also matches org.secret_scanning_custom_pattern_push_protection_disabled, org.secret_scanning_push_protection_disable Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.secret_scanning_push_protection_new_repos_enable
#Description
Push protection for secret scanning was enabled for all new repositories in the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957526673,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjM=",
"action": "org.secret_scanning_push_protection_new_repos_enable",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957526673,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4C0365:F98C832:6A550816",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user": "user",
"user_agent": "python-requests/2.34.2",
"user_id": 9000002
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.security_center_export_code_scanning_metrics
#Description
A CSV export was requested on the CodeQL pull request alerts page.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.security_center_export_coverage
#Description
A CSV export was requested on the Coverage page.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.security_center_export_overview_dashboard
#Description
A CSV export was requested on the Overview Dashboard page.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.security_center_export_risk
#Description
A CSV export was requested on the Risk page.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.self_hosted_runner_offline
#Description
The runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.self_hosted_runner_online
#Description
The runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.self_hosted_runner_updated
#Description
The runner application was updated. This event is not included in the JSON/CSV export.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_actions_cache_retention_policy
#Description
The cache retention policy for GitHub Actions was set for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_actions_cache_storage_policy
#Description
The cache storage policy for GitHub Actions was set for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_actions_fork_pr_approvals_policy
#Description
The setting for requiring approvals for workflows from public forks was changed for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_actions_private_fork_pr_approvals_policy
#Description
The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_actions_retention_limit
#Description
The retention period for GitHub Actions artifacts and logs in an organization was changed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_custom_invitation_rate_limit
#Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_default_workflow_permissions
#Description
The default permissions granted to the GITHUB_TOKEN when running workflows were changed for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957678642,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMjM=",
"action": "org.set_default_workflow_permissions",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957678642,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "BF08:15A139:F7012CB:FBCA676:6A5508AE",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
Detection Rules #
Panther #
T1195T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.set_fork_pr_workflows_policy
#Description
The policy for workflows on private repository forks was changed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.set_workflow_permission_can_approve_pr
#Description
The policy for allowing GitHub Actions to create and approve pull requests was changed for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783902059483,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAxMjQ=",
"action": "org.set_workflow_permission_can_approve_pr",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"created_at": 1783902059483,
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"request_access_security_header": null,
"request_id": "E166:32DFA7:7B241A8:7F4CC8A:6A542F6B",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.sso_response
#Description
A SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your organization. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"actor_id": 9000145,
"created_at": 1785271547568.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"actor": "user",
"action": "org.sso_response",
"issuer": "https://example.invalid/00000000-0000-0000-0000-000000000000/",
"business": "example-business",
"request_id": 9000146,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"operation_type": "authentication",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.transfer
#Description
An organization was transferred between enterprise accounts.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1020, T1537↳ also matches org.transfer_outgoing Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.transfer_outgoing
#Description
An organization was transferred between enterprise accounts.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1020, T1537↳ also matches org.transfer YARA-L #
T1537Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.unarchive
#Description
The organization was unarchived.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.unblock_user
#Description
A user was unblocked from an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783960673259,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwMDE=",
"action": "org.unblock_user",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"blocked_user": "user",
"business": "example-business",
"business_id": 9000003,
"created_at": 1783960673259,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"operation_type": "remove",
"org": "example-org",
"org_id": 9000002,
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "A0A0:34D35:F2CFFDD:F7B8B2F:6A551461",
"token_id": 9000004,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "dw"
}
Detection Rules #
YARA-L #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_actions_secret
#Description
A GitHub Actions secret was updated for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"actor_id": 9000147,
"created_at": 1782634557072.0,
"business_id": 9000005,
"actor_is_bot": true,
"actor_is_agent": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"actor": "user",
"action": "org.update_actions_secret",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000148,
"user_agent": "PyGithub/Python",
"visibility": "selected",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxMw==",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"programmatic_access_type": "GitHub App server-to-server token"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_actions_settings
#Description
An organization owner or site administrator updated GitHub Actions policy settings for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"actor_id": 9000149,
"created_at": 1785269780657.0,
"business_id": 9000005,
"actor_is_bot": true,
"actor_is_agent": false,
"updated_github_owned_allowed": true,
"org": "example-org",
"actor": "user",
"action": "org.update_actions_settings",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000150,
"user_agent": "go-github/v88.0.0",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxNA==",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"programmatic_access_type": "GitHub App server-to-server token"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_actions_variable
#Description
A GitHub Actions variable was updated for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000002,
"actor_id": 9000084,
"created_at": 1781613972553.0,
"business_id": 9000005,
"actor_is_bot": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"actor": "user",
"action": "org.update_actions_variable",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000151,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_custom_images_policy
#Description
The enterprise updated GitHub Actions custom image policy settings for an organization.
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.update_default_repository_permission
#Description
The default repository permission level for organization members was changed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783957523028,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNzA=",
"action": "org.update_default_repository_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783957523028,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwMQ==",
"old_permission": "read",
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"permission": "write",
"programmatic_access_type": "Personal access token (classic)",
"request_access_security_header": null,
"request_id": "EA04:7E563:F4BEE40:F98B2CC:6A550812",
"token_id": 9000006,
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"user_agent": "python-requests/2.34.2"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_immutable_releases_settings_policy
#Description
The settings policy for immutable releases was updated for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.update_integration_secret
#Description
A Codespaces or Dependabot secret was updated for an organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.update_member
#Description
A person's role was changed from owner to member or member to owner.
Documented on GitHub's enterprise audit log reference. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000092,
"user_id": 9000152,
"actor_id": 9000153,
"created_at": 1782229563399.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"user": "user",
"actor": "user",
"action": "org.update_member",
"actor_ip": "ip-redacted",
"business": "example-business",
"permission": "admin",
"request_id": 9000154,
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"old_permission": "read",
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Common Indicators #
Field Kind Value Rules Vendors github.permission (elastic rule field)eq admin1 rule elastic Detection Rules #
Elastic #
T1098, T1098.003Panther #
T1098T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_member_repository_creation_permission
#Description
The create repository permission for organization members was changed.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000008,
"actor_id": 9000155,
"created_at": 1781632041373.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"actor": "user",
"action": "org.update_member_repository_creation_permission",
"actor_ip": "ip-redacted",
"business": "example-business",
"permission": "false",
"request_id": 9000156,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "all",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_member_repository_invitation_permission
#Description
An organization owner changed the policy setting for organization members inviting outside collaborators to repositories.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"@timestamp": 1783913111740,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAwNjA=",
"action": "org.update_member_repository_invitation_permission",
"actor": "user",
"actor_id": 9000002,
"actor_is_bot": false,
"actor_location": {
"country_code": "XX"
},
"business": "example-business",
"business_id": 9000003,
"created_at": 1783913111740,
"operation_type": "modify",
"org": "example-org",
"org_id": 9000004,
"permission": false,
"request_access_security_header": null,
"request_id": "C4B6:1E91F2:841037E:888CFBC:6A545A96",
"user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/145.0.7632.6 Safari/537.36"
}
Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_new_repository_default_branch_setting
#Description
The name of the default branch was changed for new repositories in the organization.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.update_repo_self_hosted_runners_policy
#Description
The repository self-hosted runners policy was updated
Documented on GitHub's organization audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more
org.update_saml_provider_settings
#Description
An organization's SAML provider settings were updated.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"org_id": 9000157,
"actor_id": 9000031,
"created_at": 1783416189373.0,
"business_id": 9000005,
"actor_is_bot": false,
"org": "example-org",
"actor": "user",
"action": "org.update_saml_provider_settings",
"issuer": "https://example.invalid/00000000-0000-0000-0000-000000000000/",
"sso_url": "https://example.invalid/00000000-0000-0000-0000-000000000000/saml2",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000158,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
YARA-L #
T1562↳ also matches org.disable_saml Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more References #
org.update_terms_of_service
#Description
An organization changed between the Standard Terms of Service and the GitHub Customer Agreement.
Documented on GitHub's enterprise audit log reference. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
T1098↳ also matches org.accept_business_invitation, org.add_billing_manager, org.add_disallowed_two_factor_method, org.add_member, org.add_outside_collaborator, org.add_security_manager, and 158 more