Business Secret Scanning
| action | Description | Sample | Rule |
|---|---|---|---|
| business_ | Secret scanning was disabled for your enterprise. | N | Y |
| business_ | Secret scanning was disabled for new repositories in your enterprise. | N | Y |
| business_ | Secret scanning was enabled for your enterprise. | N | N |
| business_ | Secret scanning was enabled for new repositories in your enterprise. | N | N |
business_secret_scanning.disable
#Description
Secret scanning was disabled for your enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action2 detection rules Panther, Sigma Detection Rules #
Sigma #
T1685↳ also matches business_secret_scanning.disabled_for_new_repos YARA-L #
T1562↳ also matches business_secret_scanning.disabled_for_new_repos Panther #
T1562↳ also matches business_secret_scanning.disabled_for_new_repos
business_secret_scanning.disabled_for_new_repos
#Description
Secret scanning was disabled for new repositories in your enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action2 detection rules Panther, Sigma Detection Rules #
Sigma #
T1685↳ also matches business_secret_scanning.disable YARA-L #
T1562↳ also matches business_secret_scanning.disable Panther #
T1562↳ also matches business_secret_scanning.disable
business_secret_scanning.enable
#Description
Secret scanning was enabled for your enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
business_secret_scanning.enabled_for_new_repos
#Description
Secret scanning was enabled for new repositories in your enterprise.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.