IP Allow List
| action | Description | Sample | Rule |
|---|---|---|---|
| ip_ | An IP allow list was disabled. | N | Y |
| ip_ | An IP allow list was disabled for installed GitHub Apps. | N | Y |
| ip_ | Identity Provider based IP allow list for web interactions was disabled. | N | Y |
| ip_ | N | Y | |
| ip_ | IP allow list user level enforcement was disabled. | N | Y |
| ip_ | An IP allow list was enabled. | N | Y |
| ip_ | An IP allow list was enabled for installed GitHub Apps. | N | Y |
| ip_ | Identity Provider based IP allow list for web interactions was enabled. | N | Y |
| ip_ | N | Y | |
| ip_ | IP allow list user level enforcement was enabled. | N | Y |
| ip_ | N | Y |
ip_allow_list.disable
#Description
An IP allow list was disabled.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action2 detection rules Panther, Splunk Detection Rules #
Splunk #
T1195, T1685Panther #
T1098↳ also matches ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_for_installed_apps
#Description
An IP allow list was disabled for installed GitHub Apps.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_idp_ip_allowlist_for_web
#Description
Identity Provider based IP allow list for web interactions was disabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_skip_idp_ip_allowlist_app_access
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.disable_user_level_enforcement
#Description
IP allow list user level enforcement was disabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.enable, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.enable
#Description
An IP allow list was enabled.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable_for_installed_apps, and 4 more
ip_allow_list.enable_for_installed_apps
#Description
An IP allow list was enabled for installed GitHub Apps.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.enable_idp_ip_allowlist_for_web
#Description
Identity Provider based IP allow list for web interactions was enabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.enable_skip_idp_ip_allowlist_app_access
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.enable_user_level_enforcement
#Description
IP allow list user level enforcement was enabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more
ip_allow_list.update_ip_allowlist_configuration
#Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
T1098↳ also matches ip_allow_list.disable, ip_allow_list.disable_for_installed_apps, ip_allow_list.disable_idp_ip_allowlist_for_web, ip_allow_list.disable_skip_idp_ip_allowlist_app_access, ip_allow_list.disable_user_level_enforcement, ip_allow_list.enable, and 4 more