Repo

actionDescriptionSampleRule
repo.accessThe visibility of a repository changed.YY
repo.actions_enabledGitHub Actions was enabled for a repository.YN
repo.add_memberA collaborator was added to a repository.YY
repo.add_topicA topic was added to a repository.YN
repo.advanced_security_disabledGitHub Advanced Security was disabled for a repository.NY
repo.advanced_security_enabledGitHub Advanced Security was enabled for a repository.NN
repo.archivedA repository was archived.YY
repo.change_merge_settingPull request merge options were changed for a repository.YN
repo.code_scanning_ai_findings_disabledAI-powered findings for code scanning were disabled for a repository.NN
repo.code_scanning_ai_findings_enabledAI-powered findings for code scanning were enabled for a repository.NN
repo.code_scanning_analysis_deletedCode scanning analysis for a repository was deleted.NN
repo.code_scanning_autofix_disabledAutofix for code scanning alerts was disabled for a repository.NN
repo.code_scanning_autofix_enabledAutofix for code scanning alerts was enabled for a repository.NN
repo.code_scanning_autofix_third_party_tools_disabledAutofix for third party tools for code scanning alerts was disabled for a repository.NN
repo.code_scanning_autofix_third_party_tools_enabledAutofix for third party tools for code scanning alerts was enabled for a repository.NN
repo.code_scanning_configuration_for_branch_deletedA code scanning configuration for a branch of a repository was deleted.NN
repo.code_scanning_delegated_alert_dismissal_disabledPrevention of direct alert dismissal for code scanning was disabled for a repository.NN
repo.code_scanning_delegated_alert_dismissal_enabledPrevention of direct alert dismissal for code scanning was enabled for a repository.NN
repo.codeql_disabledCode scanning using the default setup was disabled for a repository.NN
repo.codeql_enabledCode scanning using the default setup was enabled for a repository.YN
repo.codeql_updatedCode scanning using the default setup was updated for a repository.NN
repo.codespaces_trusted_repo_access_grantedGitHub Codespaces was granted trusted repository access to this repository.NN
repo.codespaces_trusted_repo_access_revokedGitHub Codespaces trusted repository access to this repository was revoked.NN
repo.config.disable_collaborators_onlyThe interaction limit for collaborators only was disabled.NN
repo.config.disable_contributors_onlyThe interaction limit for prior contributors only was disabled in a repository.NN
repo.config.disable_sockpuppet_disallowedThe interaction limit for existing users only was disabled in a repository.NN
repo.config.enable_collaborators_onlyThe interaction limit for collaborators only was enabled in a repository Users that are not collaborators or organization members were unable to interact with a repository for a set duration.NN
repo.config.enable_contributors_onlyThe interaction limit for prior contributors only was enabled in a repository Users that are not prior contributors, collaborators or organization members were unable to interact with a repository for a set duration.NN
repo.config.enable_sockpuppet_disallowedThe interaction limit for existing users was enabled in a repository New users aren't able to interact with a repository for a set duration Existing users of the repository, contributors, collaborators or organization members are able to interact with a repository.NN
repo.configure_self_hosted_jit_runnerA new just-in-time GitHub Actions self-hosted runner was configuredYN
repo.createA repository was created.YY
repo.create_actions_secretA GitHub Actions secret was created for a repository.YY
repo.create_actions_variableA GitHub Actions variable was created for a repository.YN
repo.create_integration_secretA Codespaces or Dependabot secret was created for a repository.NN
repo.destroyA repository was deleted.YY
repo.download_zipA source code archive of a repository was downloaded as a ZIP file.YY
repo.immutable_releases_settings_disabledThe setting for immutable releases was disabled for a repository.YN
repo.immutable_releases_settings_enabledThe setting for immutable releases was enabled for a repository.NN
repo.pages_cnameA GitHub Pages custom domain was modified in a repository.YN
repo.pages_createA GitHub Pages site was created.YN
repo.pages_destroyA GitHub Pages site was deleted.YN
repo.pages_https_redirect_disabledHTTPS redirects were disabled for a GitHub Pages site.YN
repo.pages_https_redirect_enabledHTTPS redirects were enabled for a GitHub Pages site.NN
repo.pages_privateA GitHub Pages site visibility was changed to private.YN
repo.pages_publicA GitHub Pages site visibility was changed to public.YY
repo.pages_soft_deleteA GitHub Pages site was soft-deleted because its owner's plan changed.NN
repo.pages_soft_delete_restoreA GitHub Pages site that was previously soft-deleted was restored.NN
repo.pages_sourceA GitHub Pages source was modified.YN
repo.register_self_hosted_runnerA new self-hosted runner was registered.YY
repo.remove_actions_secretA GitHub Actions secret was deleted for a repository.YN
repo.remove_actions_variableA GitHub Actions variable was deleted for a repository.YN
repo.remove_integration_secretA Codespaces or Dependabot secret was deleted for a repository.NN
repo.remove_memberA collaborator was removed from a repository.YY
repo.remove_self_hosted_runnerA self-hosted runner was removed.YY
repo.remove_topicA topic was removed from a repository.YN
repo.renameA repository was renamed.YN
repo.rename_branchA branch was renamed.YN
repo.restoreNN
repo.self_hosted_runner_offlineThe runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.NN
repo.self_hosted_runner_onlineThe runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.NN
repo.self_hosted_runner_updatedThe runner application was updated. This event is not included in the JSON/CSV export.NN
repo.set_actions_cache_retention_policyThe cache retention policy for GitHub Actions was set for a repository.NN
repo.set_actions_cache_storage_policyThe cache storage policy for GitHub Actions was set for a repository.YN
repo.set_actions_fork_pr_approvals_policyThe setting for requiring approvals for workflows from public forks was changed for a repository.YN
repo.set_actions_private_fork_pr_approvals_policyThe policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for a repository.NN
repo.set_actions_retention_limitThe retention period for GitHub Actions artifacts and logs in a repository was changed.NN
repo.set_default_workflow_permissionsThe default permissions granted to the GITHUB_TOKEN when running workflows were changed for a repository.YN
repo.set_fork_pr_workflows_policyTriggered when the policy for workflows on private repository forks is changed.NN
repo.set_workflow_permission_can_approve_prThe policy for allowing GitHub Actions to create and approve pull requests was changed for a repository.YN
repo.staff_unlockAn enterprise owner or GitHub staff (with permission from a repository administrator) temporarily unlocked the repository.NN
repo.temporary_access_grantedTemporary access was enabled for a repository.NN
repo.transferA user accepted a request to receive a transferred repository.YY
repo.transfer_outgoingA repository was transferred to another repository network.YY
repo.transfer_startA user sent a request to transfer a repository to another user or organization.NY
repo.unarchivedA repository was unarchived.YY
repo.update_actions_access_settingsThe setting to control how a repository was used by GitHub Actions workflows in other repositories was changed.NN
repo.update_actions_secretA GitHub Actions secret was updated for a repository.YN
repo.update_actions_settingsA repository administrator changed GitHub Actions policy settings for a repository.YN
repo.update_actions_variableA GitHub Actions variable was updated for a repository.YN
repo.update_default_branchThe default branch for a repository was changed.YN
repo.update_integration_secretA Codespaces or Dependabot secret was updated for a repository.YN
repo.update_memberA user's permission to a repository was changed.YN

repo.access

#
Category
repo

Description

The visibility of a repository changed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "repo_id": 9000274,
  "actor_id": 9000047,
  "created_at": 1784578057679.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.access",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000275,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "previous_visibility": "internal",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

YARA-L #

Panther #

References #

repo.actions_enabled

#
Category
repo

Description

GitHub Actions was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000046,
  "actor_id": 9000002,
  "created_at": 1784577549752.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.actions_enabled",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000049,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.add_member

#
Category
repo

Description

A collaborator was added to a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000092,
  "repo_id": 9000276,
  "user_id": 9000093,
  "actor_id": 9000092,
  "created_at": 1783271784506.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "user": "user",
  "actor": "user",
  "action": "repo.add_member",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "permission": "admin",
  "request_id": 9000094,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

repo.add_topic

#
Category
repo

Description

A topic was added to a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000277,
  "user_id": 9000182,
  "actor_id": 9000182,
  "created_at": 1784823443238.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "user": "user",
  "actor": "user",
  "topic": "example-label-145",
  "action": "repo.add_topic",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000278,
  "user_agent": "example.invalid/3.2.2 example.invalid/5.2.2 example.invalid/24",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxOQ==",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "programmatic_access_type": "GitHub App server-to-server token"
}

References #

repo.advanced_security_disabled

#
Category
repo

Description

GitHub Advanced Security was disabled for a repository.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

repo.advanced_security_enabled

#
Category
repo

Description

GitHub Advanced Security was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.archived

#
Category
repo

Description

A repository was archived.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000279,
  "actor_id": 9000215,
  "created_at": 1785261086271.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.archived",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000280,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Splunk #

  • GitHub Enterprise Repository Archived source: The following analytic detects when a repository is archived in GitHub Enterprise. The detection monitors GitHub Enterprise audit logs for repository archival events by tracking actor details, repository information, and associated…T1195, T1485
  • GitHub Organizations Repository Archived source: The following analytic detects when a repository is archived in GitHub Organizations. The detection monitors GitHub Organizations audit logs for repository archival events by tracking actor details, repository information, and associated…T1195, T1485

YARA-L #

Panther #

References #

repo.change_merge_setting

#
Category
repo

Description

Pull request merge options were changed for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000281,
  "actor_id": 9000282,
  "created_at": 1785261426378.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.change_merge_setting",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000283,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.code_scanning_ai_findings_disabled

#
Category
repo

Description

AI-powered findings for code scanning were disabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_ai_findings_enabled

#
Category
repo

Description

AI-powered findings for code scanning were enabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_analysis_deleted

#
Category
repo

Description

Code scanning analysis for a repository was deleted.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_autofix_disabled

#
Category
repo

Description

Autofix for code scanning alerts was disabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_autofix_enabled

#
Category
repo

Description

Autofix for code scanning alerts was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_autofix_third_party_tools_disabled

#
Category
repo

Description

Autofix for third party tools for code scanning alerts was disabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_autofix_third_party_tools_enabled

#
Category
repo

Description

Autofix for third party tools for code scanning alerts was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_configuration_for_branch_deleted

#
Category
repo

Description

A code scanning configuration for a branch of a repository was deleted.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_delegated_alert_dismissal_disabled

#
Category
repo

Description

Prevention of direct alert dismissal for code scanning was disabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.code_scanning_delegated_alert_dismissal_enabled

#
Category
repo

Description

Prevention of direct alert dismissal for code scanning was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.codeql_disabled

#
Category
repo

Description

Code scanning using the default setup was disabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.codeql_enabled

#
Category
repo

Description

Code scanning using the default setup was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000097,
  "repo_id": 9000284,
  "actor_id": 9000285,
  "created_at": 1783531855159.0,
  "business_id": 9000005,
  "public_repo": true,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "topic": "example-label-116",
  "action": "repo.codeql_enabled",
  "business": "example-business",
  "query_suite": "default",
  "threat_model": "remote",
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.codeql_updated

#
Category
repo

Description

Code scanning using the default setup was updated for a repository.

Documented on GitHub's enterprise audit log reference.

repo.codespaces_trusted_repo_access_granted

#
Category
repo

Description

GitHub Codespaces was granted trusted repository access to this repository.

Documented on GitHub's enterprise audit log reference.

repo.codespaces_trusted_repo_access_revoked

#
Category
repo

Description

GitHub Codespaces trusted repository access to this repository was revoked.

Documented on GitHub's enterprise audit log reference.

repo.config.disable_collaborators_only

#
Category
repo

Description

The interaction limit for collaborators only was disabled.

Documented on GitHub's enterprise audit log reference.

repo.config.disable_contributors_only

#
Category
repo

Description

The interaction limit for prior contributors only was disabled in a repository.

Documented on GitHub's enterprise audit log reference.

repo.config.disable_sockpuppet_disallowed

#
Category
repo

Description

The interaction limit for existing users only was disabled in a repository.

Documented on GitHub's enterprise audit log reference.

repo.config.enable_collaborators_only

#
Category
repo

Description

The interaction limit for collaborators only was enabled in a repository Users that are not collaborators or organization members were unable to interact with a repository for a set duration.

Documented on GitHub's enterprise audit log reference.

repo.config.enable_contributors_only

#
Category
repo

Description

The interaction limit for prior contributors only was enabled in a repository Users that are not prior contributors, collaborators or organization members were unable to interact with a repository for a set duration.

Documented on GitHub's enterprise audit log reference.

repo.config.enable_sockpuppet_disallowed

#
Category
repo

Description

The interaction limit for existing users was enabled in a repository New users aren't able to interact with a repository for a set duration Existing users of the repository, contributors, collaborators or organization members are able to interact with a repository.

Documented on GitHub's enterprise audit log reference.

repo.configure_self_hosted_jit_runner

#
Category
repo

Description

A new just-in-time GitHub Actions self-hosted runner was configured

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000286,
  "actor_id": 9000287,
  "created_at": 1780432407027.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.configure_self_hosted_jit_runner",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000288,
  "user_agent": "go-github/v71.0.0",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMA==",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "programmatic_access_type": "GitHub App server-to-server token"
}

References #

repo.create

#
Category
repo

Description

A repository was created.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000092,
  "repo_id": 9000276,
  "actor_id": 9000093,
  "created_at": 1783271785041.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.create",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000094,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "request_category": "other",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

Panther #

References #

repo.create_actions_secret

#
Category
repo

Description

A GitHub Actions secret was created for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000074,
  "actor_id": 9000060,
  "created_at": 1781549189546.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.create_actions_secret",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000289,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

repo.create_actions_variable

#
Category
repo

Description

A GitHub Actions variable was created for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000040,
  "repo_id": 9000290,
  "actor_id": 9000041,
  "created_at": 1781289961896.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.create_actions_variable",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000291,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.create_integration_secret

#
Category
repo

Description

A Codespaces or Dependabot secret was created for a repository.

Documented on GitHub's enterprise audit log reference.

repo.destroy

#
Category
repo

Description

A repository was deleted.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000092,
  "repo_id": 9000276,
  "actor_id": 9000093,
  "created_at": 1783272076548.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.destroy",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000292,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "request_category": "other",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • GitHub Repository Deleted source medium: This rule detects when a GitHub repository is deleted within your organization. Repositories are a critical component used within an organization to manage work, collaborate with others and release products to the public. Any delete action against a repository should be investigated to determine it's validity. Unauthorized deletion of organization repositories could cause irreversible loss of intellectual property and indicate compromise within your organization.T1485

Splunk #

  • GitHub Enterprise Repository Deleted source: The following analytic detects when a user deletes a repository in GitHub Enterprise. The detection monitors GitHub Enterprise audit logs for repository deletion events, which could indicate unauthorized removal of critical source code and…T1195, T1485
  • GitHub Organizations Repository Deleted source: The following analytic identifies when a repository is deleted within a GitHub organization. The detection monitors GitHub Organizations audit logs for repository deletion events by tracking actor details, repository information, and…T1195, T1485

Kusto #

YARA-L #

References #

repo.download_zip

#
Category
repo

Description

A source code archive of a repository was downloaded as a ZIP file.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000293,
  "actor_id": 9000294,
  "created_at": 1785269893145.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.download_zip",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000295,
  "user_agent": "Apache-HttpClient/UNAVAILABLE (Java/21.0.11),AWS Security Agent",
  "visibility": "private",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMQ==",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "access",
  "programmatic_access_type": "GitHub App server-to-server token"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

  • NX Supply Chain - S1ngularity Repository Detection source: https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c Detects GitHub activity associated with the NX supply chain compromise (CVE-2024-XXXX). The s1ngularity attack compromised popular NX build system packages affecting ~4M weekly downloads. Attack Details: - Malicious NPM packages published August 26-27, 2025 (22:32-03:37 UTC) - Created repositories: "s1ngularity-repository", "s1ngularity-repository-0/1" for data exfiltration - Targeted cryptocurrency wallets, SSH keys, GitHub/NPM tokens, .env files - Used triple base64 encoding to upload stolen credentials - First documented case of weaponizing AI CLI tools for reconnaissance This query detects repository creation, access, and API activity patterns consistent with the attack.↳ also matches repo.access, repo.create

References #

repo.immutable_releases_settings_disabled

#
Category
repo

Description

The setting for immutable releases was disabled for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000296,
  "actor_id": 9000084,
  "created_at": 1783612445753.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.immutable_releases_settings_disabled",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000297,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.immutable_releases_settings_enabled

#
Category
repo

Description

The setting for immutable releases was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.pages_cname

#
Category
repo

Description

A GitHub Pages custom domain was modified in a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1772492172155,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzNQ==",
  "action": "repo.pages_cname",
  "actor": "user",
  "actor_id": 9000002,
  "cname": "example.com",
  "created_at": 1772492172155,
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwNQAAAAAAAAA=",
  "oauth_application_id": 9200001,
  "old_cname": null,
  "operation_type": "modify",
  "programmatic_access_type": "OAuth access token",
  "public_repo": true,
  "repo": "user/example-repo",
  "repo_id": 9100000002,
  "request_access_security_header": null,
  "request_id": "812A:273886:2655780:26DADAA:69A6158B",
  "token_id": 9300000004,
  "token_scopes": "admin:public_key,gist,read:org,repo,workflow",
  "user": "user",
  "user_agent": "GitHub CLI 2.87.3",
  "user_id": 9000002,
  "visibility": "public"
}

References #

repo.pages_create

#
Category
repo

Description

A GitHub Pages site was created.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000298,
  "actor_id": 9000132,
  "created_at": 1784899256670.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.pages_create",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000299,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.pages_destroy

#
Category
repo

Description

A GitHub Pages site was deleted.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1772495640403,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzNw==",
  "action": "repo.pages_destroy",
  "actor": "user",
  "actor_id": 9000002,
  "created_at": 1772495640403,
  "operation_type": "remove",
  "public_repo": false,
  "repo": "user/example-repo",
  "repo_id": 9100000002,
  "request_access_security_header": null,
  "request_id": "D728:14548D:2797DF1:2824828:69A62308",
  "user": "user",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
  "user_id": 9000002,
  "visibility": "private"
}

References #

repo.pages_https_redirect_disabled

#
Category
repo

Description

HTTPS redirects were disabled for a GitHub Pages site.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1772315857218,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzOA==",
  "action": "repo.pages_https_redirect_disabled",
  "actor": "user",
  "actor_id": 9000002,
  "created_at": 1772315857218,
  "operation_type": "modify",
  "public_repo": true,
  "repo": "user/example-repo",
  "repo_id": 9100000002,
  "request_access_security_header": null,
  "request_id": "D1E4:3F47F0:11992D4:157390B:69A364CE",
  "user": "user",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
  "user_id": 9000002,
  "visibility": "public"
}

References #

repo.pages_https_redirect_enabled

#
Category
repo

Description

HTTPS redirects were enabled for a GitHub Pages site.

Documented on GitHub's enterprise audit log reference.

repo.pages_private

#
Category
repo

Description

A GitHub Pages site visibility was changed to private.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000298,
  "actor_id": 9000132,
  "created_at": 1784899256739.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.pages_private",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000299,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.pages_public

#
Category
repo

Description

A GitHub Pages site visibility was changed to public.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1772485305537,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzOQ==",
  "action": "repo.pages_public",
  "actor": "user",
  "actor_id": 9000002,
  "created_at": 1772485305537,
  "operation_type": "modify",
  "public_repo": true,
  "repo": "user/example-repo",
  "repo_id": 9100000002,
  "request_access_security_header": null,
  "request_id": "CD2C:3567FA:187CDCC:18CB04F:69A5FAB0",
  "user": "user",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
  "user_id": 9000002,
  "visibility": "public"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

repo.pages_soft_delete

#
Category
repo

Description

A GitHub Pages site was soft-deleted because its owner's plan changed.

Documented on GitHub's enterprise audit log reference.

repo.pages_soft_delete_restore

#
Category
repo

Description

A GitHub Pages site that was previously soft-deleted was restored.

Documented on GitHub's enterprise audit log reference.

repo.pages_source

#
Category
repo

Description

A GitHub Pages source was modified.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000298,
  "actor_id": 9000132,
  "created_at": 1784899256732.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.pages_source",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000299,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.register_self_hosted_runner

#
Category
repo

Description

A new self-hosted runner was registered.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000218,
  "actor_id": 9000028,
  "created_at": 1785241073436.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.register_self_hosted_runner",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000300,
  "user_agent": "GitHubActionsRunner-linux-x64/2.335.1 CommitSHA/gggggggggggggggggggggggggggggggggggggggg Pid/40 CreationTime/2026-07-28T12%3A17%3A47.9481369Z (Runner)",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "create"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

References #

repo.remove_actions_secret

#
Category
repo

Description

A GitHub Actions secret was deleted for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "repo_id": 9000112,
  "actor_id": 9000113,
  "created_at": 1784292004129.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.remove_actions_secret",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000301,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.remove_actions_variable

#
Category
repo

Description

A GitHub Actions variable was deleted for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000302,
  "actor_id": 9000084,
  "token_id": 9000303,
  "created_at": 1782769218392.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "oauth_application_id": 9000044,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.remove_actions_variable",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000304,
  "user_agent": "PyGithub/Python",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMg==",
  "token_scopes": "gist,read:org,repo,workflow",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "external_identity_nameid": "user",
  "programmatic_access_type": "OAuth access token",
  "external_identity_username": "user"
}

References #

repo.remove_integration_secret

#
Category
repo

Description

A Codespaces or Dependabot secret was deleted for a repository.

Documented on GitHub's enterprise audit log reference.

repo.remove_member

#
Category
repo

Description

A collaborator was removed from a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000274,
  "user_id": 9000285,
  "actor_id": 9000002,
  "created_at": 1784578092176.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "user": "user",
  "actor": "user",
  "action": "repo.remove_member",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000305,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

repo.remove_self_hosted_runner

#
Category
repo

Description

A self-hosted runner was removed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000306,
  "actor_id": 9000307,
  "created_at": 1784237864073.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.remove_self_hosted_runner",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000308,
  "user_agent": "go-github/v84.0.0",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMw==",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "remove",
  "programmatic_access_type": "GitHub App server-to-server token"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

repo.remove_topic

#
Category
repo

Description

A topic was removed from a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000309,
  "user_id": 9000182,
  "created_at": 1782117787224.0,
  "business_id": 9000005,
  "public_repo": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "user": "user",
  "topic": "example-label-117",
  "action": "repo.remove_topic",
  "business": "example-business",
  "operation_type": "remove"
}

References #

repo.rename

#
Category
repo

Description

A repository was renamed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000310,
  "actor_id": 9000311,
  "created_at": 1783664367273.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.rename",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "old_name": "example-repo",
  "request_id": 9000312,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.rename_branch

#
Category
repo

Description

A branch was renamed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000313,
  "actor_id": 9000314,
  "created_at": 1785161728370.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "default_branch": true,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.rename_branch",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "new_branch": "main",
  "old_branch": "master",
  "request_id": 9000315,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.restore

#
Category
repo

Documented on GitHub's enterprise audit log reference.

repo.self_hosted_runner_offline

#
Category
repo

Description

The runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented on GitHub's enterprise audit log reference.

repo.self_hosted_runner_online

#
Category
repo

Description

The runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.

Documented on GitHub's enterprise audit log reference.

repo.self_hosted_runner_updated

#
Category
repo

Description

The runner application was updated. This event is not included in the JSON/CSV export.

Documented on GitHub's enterprise audit log reference.

repo.set_actions_cache_retention_policy

#
Category
repo

Description

The cache retention policy for GitHub Actions was set for a repository.

Documented on GitHub's enterprise audit log reference.

repo.set_actions_cache_storage_policy

#
Category
repo

Description

The cache storage policy for GitHub Actions was set for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000268,
  "actor_id": 9000047,
  "created_at": 1780598516273.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.set_actions_cache_storage_policy",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000316,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.set_actions_fork_pr_approvals_policy

#
Category
repo

Description

The setting for requiring approvals for workflows from public forks was changed for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "@timestamp": 1772318151374,
  "_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDA0NA==",
  "action": "repo.set_actions_fork_pr_approvals_policy",
  "actor": "user",
  "actor_id": 9000002,
  "created_at": 1772318151374,
  "operation_type": "modify",
  "policy": "ALL_OUTSIDE_COLLABORATORS",
  "public_repo": true,
  "repo": "user/example-repo",
  "repo_id": 9100000002,
  "request_access_security_header": null,
  "request_id": "D334:209D2E:13C165B:17CCC73:69A36DC7",
  "user": "user",
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
  "user_id": 9000002,
  "visibility": "public"
}

References #

repo.set_actions_private_fork_pr_approvals_policy

#
Category
repo

Description

The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for a repository.

Documented on GitHub's enterprise audit log reference.

repo.set_actions_retention_limit

#
Category
repo

Description

The retention period for GitHub Actions artifacts and logs in a repository was changed.

Documented on GitHub's enterprise audit log reference.

repo.set_default_workflow_permissions

#
Category
repo

Description

The default permissions granted to the GITHUB_TOKEN when running workflows were changed for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000317,
  "actor_id": 9000068,
  "created_at": 1781642275441.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.set_default_workflow_permissions",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000318,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "internal",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.set_fork_pr_workflows_policy

#
Category
repo

Description

Triggered when the policy for workflows on private repository forks is changed.

Documented on GitHub's enterprise audit log reference.

repo.set_workflow_permission_can_approve_pr

#
Category
repo

Description

The policy for allowing GitHub Actions to create and approve pull requests was changed for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000317,
  "actor_id": 9000068,
  "created_at": 1781642275459.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.set_workflow_permission_can_approve_pr",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000318,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "internal",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.staff_unlock

#
Category
repo

Description

An enterprise owner or GitHub staff (with permission from a repository administrator) temporarily unlocked the repository.

Documented on GitHub's enterprise audit log reference.

repo.temporary_access_granted

#
Category
repo

Description

Temporary access was enabled for a repository.

Documented on GitHub's enterprise audit log reference.

repo.transfer

#
Category
repo

Description

A user accepted a request to receive a transferred repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000274,
  "actor_id": 9000047,
  "created_at": 1784578093901.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "owner": "example-org-1",
  "action": "repo.transfer",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "old_user": "example-business-1",
  "repo_was": "example-business-1/example-repo-181",
  "request_id": 9000305,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "transfer",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

repo.transfer_outgoing

#
Category
repo

Description

A repository was transferred to another repository network.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "repo_id": 9000046,
  "actor_id": 9000047,
  "created_at": 1784577551724.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.transfer_outgoing",
  "new_nwo": "example-org-1/example-repo-100",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000049,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "transfer",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

YARA-L #

Panther #

References #

repo.transfer_start

#
Category
repo

Description

A user sent a request to transfer a repository to another user or organization.

Documented on GitHub's enterprise audit log reference.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

repo.unarchived

#
Category
repo

Description

A repository was unarchived.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000279,
  "actor_id": 9000229,
  "created_at": 1783958357712.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.unarchived",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000319,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

repo.update_actions_access_settings

#
Category
repo

Description

The setting to control how a repository was used by GitHub Actions workflows in other repositories was changed.

Documented on GitHub's enterprise audit log reference.

repo.update_actions_secret

#
Category
repo

Description

A GitHub Actions secret was updated for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000008,
  "repo_id": 9000320,
  "actor_id": 9000321,
  "created_at": 1784810815510.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.update_actions_secret",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000322,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.update_actions_settings

#
Category
repo

Description

A repository administrator changed GitHub Actions policy settings for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000323,
  "actor_id": 9000055,
  "token_id": 9000324,
  "created_at": 1782765406126.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "updated_access_policy": true,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.update_actions_settings",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "new_policy": "all",
  "old_policy": "none",
  "request_id": 9000325,
  "user_agent": "GitHub CLI 2.45.0",
  "visibility": "private",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyNA==",
  "token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "programmatic_access_type": "Personal access token (classic)",
  "external_identity_username": "user"
}

References #

repo.update_actions_variable

#
Category
repo

Description

A GitHub Actions variable was updated for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000326,
  "actor_id": 9000155,
  "created_at": 1781722421899.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.update_actions_variable",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000327,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.update_default_branch

#
Category
repo

Description

The default branch for a repository was changed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000313,
  "actor_id": 9000314,
  "created_at": 1785161727276.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.update_default_branch",
  "changes": {
    "default_branch": "main",
    "old_default_branch": "master"
  },
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000315,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #

repo.update_integration_secret

#
Category
repo

Description

A Codespaces or Dependabot secret was updated for a repository.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000097,
  "repo_id": 9000328,
  "actor_id": 9000329,
  "created_at": 1783987254324.0,
  "business_id": 9000005,
  "public_repo": true,
  "actor_is_bot": true,
  "actor_is_agent": false,
  "key": "DEPLOY_SYNTHETIC",
  "org": "example-org",
  "repo": "user/example-repo",
  "actor": "user",
  "action": "repo.update_integration_secret",
  "business": "example-business",
  "request_id": 9000330,
  "user_agent": "Octokit Ruby Gem 10.0.0",
  "integration": "example-label-118",
  "hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyNQ==",
  "operation_type": "modify",
  "programmatic_access_type": "GitHub App server-to-server token"
}

References #

repo.update_member

#
Category
repo

Description

A user's permission to a repository was changed.

Documented on GitHub's enterprise audit log reference.

Example Audit Log Entry #

{
  "org_id": 9000002,
  "repo_id": 9000331,
  "user_id": 9000332,
  "actor_id": 9000333,
  "created_at": 1784538009284.0,
  "business_id": 9000005,
  "public_repo": false,
  "actor_is_bot": false,
  "org": "example-org",
  "repo": "user/example-repo",
  "user": "user",
  "actor": "user",
  "action": "repo.update_member",
  "actor_ip": "ip-redacted",
  "business": "example-business",
  "request_id": 9000334,
  "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
  "visibility": "private",
  "actor_location": {
    "country_code": "XX"
  },
  "operation_type": "modify",
  "old_permissions": {
    "admin": false,
    "maintain": false,
    "pull": true,
    "push": true,
    "triage": true
  },
  "new_repo_permission": "read",
  "old_repo_permission": "write",
  "external_identity_nameid": "user",
  "external_identity_username": "user"
}

References #