Repo
| action | Description | Sample | Rule |
|---|---|---|---|
| repo. | The visibility of a repository changed. | Y | Y |
| repo. | GitHub Actions was enabled for a repository. | Y | N |
| repo. | A collaborator was added to a repository. | Y | Y |
| repo. | A topic was added to a repository. | Y | N |
| repo. | GitHub Advanced Security was disabled for a repository. | N | Y |
| repo. | GitHub Advanced Security was enabled for a repository. | N | N |
| repo. | A repository was archived. | Y | Y |
| repo. | Pull request merge options were changed for a repository. | Y | N |
| repo. | AI-powered findings for code scanning were disabled for a repository. | N | N |
| repo. | AI-powered findings for code scanning were enabled for a repository. | N | N |
| repo. | Code scanning analysis for a repository was deleted. | N | N |
| repo. | Autofix for code scanning alerts was disabled for a repository. | N | N |
| repo. | Autofix for code scanning alerts was enabled for a repository. | N | N |
| repo. | Autofix for third party tools for code scanning alerts was disabled for a repository. | N | N |
| repo. | Autofix for third party tools for code scanning alerts was enabled for a repository. | N | N |
| repo. | A code scanning configuration for a branch of a repository was deleted. | N | N |
| repo. | Prevention of direct alert dismissal for code scanning was disabled for a repository. | N | N |
| repo. | Prevention of direct alert dismissal for code scanning was enabled for a repository. | N | N |
| repo. | Code scanning using the default setup was disabled for a repository. | N | N |
| repo. | Code scanning using the default setup was enabled for a repository. | Y | N |
| repo. | Code scanning using the default setup was updated for a repository. | N | N |
| repo. | GitHub Codespaces was granted trusted repository access to this repository. | N | N |
| repo. | GitHub Codespaces trusted repository access to this repository was revoked. | N | N |
| repo. | The interaction limit for collaborators only was disabled. | N | N |
| repo. | The interaction limit for prior contributors only was disabled in a repository. | N | N |
| repo. | The interaction limit for existing users only was disabled in a repository. | N | N |
| repo. | The interaction limit for collaborators only was enabled in a repository Users that are not collaborators or organization members were unable to interact with a repository for a set duration. | N | N |
| repo. | The interaction limit for prior contributors only was enabled in a repository Users that are not prior contributors, collaborators or organization members were unable to interact with a repository for a set duration. | N | N |
| repo. | The interaction limit for existing users was enabled in a repository New users aren't able to interact with a repository for a set duration Existing users of the repository, contributors, collaborators or organization members are able to interact with a repository. | N | N |
| repo. | A new just-in-time GitHub Actions self-hosted runner was configured | Y | N |
| repo. | A repository was created. | Y | Y |
| repo. | A GitHub Actions secret was created for a repository. | Y | Y |
| repo. | A GitHub Actions variable was created for a repository. | Y | N |
| repo. | A Codespaces or Dependabot secret was created for a repository. | N | N |
| repo. | A repository was deleted. | Y | Y |
| repo. | A source code archive of a repository was downloaded as a ZIP file. | Y | Y |
| repo. | The setting for immutable releases was disabled for a repository. | Y | N |
| repo. | The setting for immutable releases was enabled for a repository. | N | N |
| repo. | A GitHub Pages custom domain was modified in a repository. | Y | N |
| repo. | A GitHub Pages site was created. | Y | N |
| repo. | A GitHub Pages site was deleted. | Y | N |
| repo. | HTTPS redirects were disabled for a GitHub Pages site. | Y | N |
| repo. | HTTPS redirects were enabled for a GitHub Pages site. | N | N |
| repo. | A GitHub Pages site visibility was changed to private. | Y | N |
| repo. | A GitHub Pages site visibility was changed to public. | Y | Y |
| repo. | A GitHub Pages site was soft-deleted because its owner's plan changed. | N | N |
| repo. | A GitHub Pages site that was previously soft-deleted was restored. | N | N |
| repo. | A GitHub Pages source was modified. | Y | N |
| repo. | A new self-hosted runner was registered. | Y | Y |
| repo. | A GitHub Actions secret was deleted for a repository. | Y | N |
| repo. | A GitHub Actions variable was deleted for a repository. | Y | N |
| repo. | A Codespaces or Dependabot secret was deleted for a repository. | N | N |
| repo. | A collaborator was removed from a repository. | Y | Y |
| repo. | A self-hosted runner was removed. | Y | Y |
| repo. | A topic was removed from a repository. | Y | N |
| repo. | A repository was renamed. | Y | N |
| repo. | A branch was renamed. | Y | N |
| repo. | N | N | |
| repo. | The runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports. | N | N |
| repo. | The runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports. | N | N |
| repo. | The runner application was updated. This event is not included in the JSON/CSV export. | N | N |
| repo. | The cache retention policy for GitHub Actions was set for a repository. | N | N |
| repo. | The cache storage policy for GitHub Actions was set for a repository. | Y | N |
| repo. | The setting for requiring approvals for workflows from public forks was changed for a repository. | Y | N |
| repo. | The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for a repository. | N | N |
| repo. | The retention period for GitHub Actions artifacts and logs in a repository was changed. | N | N |
| repo. | The default permissions granted to the GITHUB_TOKEN when running workflows were changed for a repository. | Y | N |
| repo. | Triggered when the policy for workflows on private repository forks is changed. | N | N |
| repo. | The policy for allowing GitHub Actions to create and approve pull requests was changed for a repository. | Y | N |
| repo. | An enterprise owner or GitHub staff (with permission from a repository administrator) temporarily unlocked the repository. | N | N |
| repo. | Temporary access was enabled for a repository. | N | N |
| repo. | A user accepted a request to receive a transferred repository. | Y | Y |
| repo. | A repository was transferred to another repository network. | Y | Y |
| repo. | A user sent a request to transfer a repository to another user or organization. | N | Y |
| repo. | A repository was unarchived. | Y | Y |
| repo. | The setting to control how a repository was used by GitHub Actions workflows in other repositories was changed. | N | N |
| repo. | A GitHub Actions secret was updated for a repository. | Y | N |
| repo. | A repository administrator changed GitHub Actions policy settings for a repository. | Y | N |
| repo. | A GitHub Actions variable was updated for a repository. | Y | N |
| repo. | The default branch for a repository was changed. | Y | N |
| repo. | A Codespaces or Dependabot secret was updated for a repository. | Y | N |
| repo. | A user's permission to a repository was changed. | Y | N |
repo.access
#Description
The visibility of a repository changed.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action2 detection rules Panther event.action1 detection rule Elastic extracted.fields["previous_visibility"]1 detection rule YARA-L extracted.fields["public_repo"]1 detection rule YARA-L github.category1 detection rule Elastic github.operation_type1 detection rule Elastic github.visibility1 detection rule Elastic p_event_time1 detection rule Panther Example Audit Log Entry #
{
"org_id": 9000008,
"repo_id": 9000274,
"actor_id": 9000047,
"created_at": 1784578057679.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.access",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000275,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"previous_visibility": "internal",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Elastic #
T1020, T1567, T1567.001YARA-L #
Panther #
T1567References #
repo.actions_enabled
#Description
GitHub Actions was enabled for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000046,
"actor_id": 9000002,
"created_at": 1784577549752.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.actions_enabled",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000049,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.add_member
#Description
A collaborator was added to a repository.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Example Audit Log Entry #
{
"org_id": 9000092,
"repo_id": 9000276,
"user_id": 9000093,
"actor_id": 9000092,
"created_at": 1783271784506.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"user": "user",
"actor": "user",
"action": "repo.add_member",
"actor_ip": "ip-redacted",
"business": "example-business",
"permission": "admin",
"request_id": 9000094,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1195↳ also matches repo.remove_member References #
repo.add_topic
#Description
A topic was added to a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000277,
"user_id": 9000182,
"actor_id": 9000182,
"created_at": 1784823443238.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": true,
"actor_is_agent": false,
"org": "example-org",
"repo": "user/example-repo",
"user": "user",
"actor": "user",
"topic": "example-label-145",
"action": "repo.add_topic",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000278,
"user_agent": "example.invalid/3.2.2 example.invalid/5.2.2 example.invalid/24",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAxOQ==",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"programmatic_access_type": "GitHub App server-to-server token"
}
References #
repo.advanced_security_disabled
#Description
GitHub Advanced Security was disabled for a repository.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action2 detection rules Panther, Sigma Detection Rules #
Sigma #
T1556Panther #
T1562
repo.advanced_security_enabled
#Description
GitHub Advanced Security was enabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.archived
#Description
A repository was archived.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action3 detection rules Panther, Sigma, Splunk vendor_action1 detection rule Splunk Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000279,
"actor_id": 9000215,
"created_at": 1785261086271.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.archived",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000280,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:151.0) Gecko/20100101 Firefox/151.0",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Sigma #
Splunk #
T1195, T1485T1195, T1485YARA-L #
T1485↳ also matches repo.destroy Panther #
References #
repo.change_merge_setting
#Description
Pull request merge options were changed for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000281,
"actor_id": 9000282,
"created_at": 1785261426378.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.change_merge_setting",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000283,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.code_scanning_ai_findings_disabled
#Description
AI-powered findings for code scanning were disabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_ai_findings_enabled
#Description
AI-powered findings for code scanning were enabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_analysis_deleted
#Description
Code scanning analysis for a repository was deleted.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_autofix_disabled
#Description
Autofix for code scanning alerts was disabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_autofix_enabled
#Description
Autofix for code scanning alerts was enabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_autofix_third_party_tools_disabled
#Description
Autofix for third party tools for code scanning alerts was disabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_autofix_third_party_tools_enabled
#Description
Autofix for third party tools for code scanning alerts was enabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_configuration_for_branch_deleted
#Description
A code scanning configuration for a branch of a repository was deleted.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_delegated_alert_dismissal_disabled
#Description
Prevention of direct alert dismissal for code scanning was disabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.code_scanning_delegated_alert_dismissal_enabled
#Description
Prevention of direct alert dismissal for code scanning was enabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.codeql_disabled
#Description
Code scanning using the default setup was disabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.codeql_enabled
#Description
Code scanning using the default setup was enabled for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000097,
"repo_id": 9000284,
"actor_id": 9000285,
"created_at": 1783531855159.0,
"business_id": 9000005,
"public_repo": true,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"topic": "example-label-116",
"action": "repo.codeql_enabled",
"business": "example-business",
"query_suite": "default",
"threat_model": "remote",
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.codeql_updated
#Description
Code scanning using the default setup was updated for a repository.
Documented on GitHub's enterprise audit log reference.
repo.codespaces_trusted_repo_access_granted
#Description
GitHub Codespaces was granted trusted repository access to this repository.
Documented on GitHub's enterprise audit log reference.
repo.codespaces_trusted_repo_access_revoked
#Description
GitHub Codespaces trusted repository access to this repository was revoked.
Documented on GitHub's enterprise audit log reference.
repo.config.disable_collaborators_only
#Description
The interaction limit for collaborators only was disabled.
Documented on GitHub's enterprise audit log reference.
repo.config.disable_contributors_only
#Description
The interaction limit for prior contributors only was disabled in a repository.
Documented on GitHub's enterprise audit log reference.
repo.config.disable_sockpuppet_disallowed
#Description
The interaction limit for existing users only was disabled in a repository.
Documented on GitHub's enterprise audit log reference.
repo.config.enable_collaborators_only
#Description
The interaction limit for collaborators only was enabled in a repository Users that are not collaborators or organization members were unable to interact with a repository for a set duration.
Documented on GitHub's enterprise audit log reference.
repo.config.enable_contributors_only
#Description
The interaction limit for prior contributors only was enabled in a repository Users that are not prior contributors, collaborators or organization members were unable to interact with a repository for a set duration.
Documented on GitHub's enterprise audit log reference.
repo.config.enable_sockpuppet_disallowed
#Description
The interaction limit for existing users was enabled in a repository New users aren't able to interact with a repository for a set duration Existing users of the repository, contributors, collaborators or organization members are able to interact with a repository.
Documented on GitHub's enterprise audit log reference.
repo.configure_self_hosted_jit_runner
#Description
A new just-in-time GitHub Actions self-hosted runner was configured
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000286,
"actor_id": 9000287,
"created_at": 1780432407027.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": true,
"actor_is_agent": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.configure_self_hosted_jit_runner",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000288,
"user_agent": "go-github/v71.0.0",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMA==",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"programmatic_access_type": "GitHub App server-to-server token"
}
References #
repo.create
#Description
A repository was created.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action4 detection rules Kusto, Panther event.action1 detection rule Elastic p_event_time1 detection rule Panther visibility1 detection rule Panther Example Audit Log Entry #
{
"org_id": 9000092,
"repo_id": 9000276,
"actor_id": 9000093,
"created_at": 1783271785041.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.create",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000094,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"request_category": "other",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Elastic #
T1583, T1583.006, T1648Kusto #
T1078Panther #
References #
repo.create_actions_secret
#Description
A GitHub Actions secret was created for a repository.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Sigma Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000074,
"actor_id": 9000060,
"created_at": 1781549189546.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.create_actions_secret",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000289,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Sigma #
T1078, T1078.004References #
repo.create_actions_variable
#Description
A GitHub Actions variable was created for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000040,
"repo_id": 9000290,
"actor_id": 9000041,
"created_at": 1781289961896.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.create_actions_variable",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000291,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.create_integration_secret
#Description
A Codespaces or Dependabot secret was created for a repository.
Documented on GitHub's enterprise audit log reference.
repo.destroy
#Description
A repository was deleted.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action3 detection rules Kusto, Sigma, Splunk event.action1 detection rule Elastic event.module1 detection rule Elastic vendor_action1 detection rule Splunk Example Audit Log Entry #
{
"org_id": 9000092,
"repo_id": 9000276,
"actor_id": 9000093,
"created_at": 1783272076548.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.destroy",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000292,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"request_category": "other",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Sigma #
T1213, T1213.003Elastic #
T1485Splunk #
T1195, T1485T1195, T1485Kusto #
T1078YARA-L #
T1485↳ also matches repo.archived References #
repo.download_zip
#Description
A source code archive of a repository was downloaded as a ZIP file.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther extracted.fields["public_repo"]1 detection rule YARA-L p_event_time1 detection rule Panther Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000293,
"actor_id": 9000294,
"created_at": 1785269893145.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": true,
"actor_is_agent": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.download_zip",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000295,
"user_agent": "Apache-HttpClient/UNAVAILABLE (Java/21.0.11),AWS Security Agent",
"visibility": "private",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMQ==",
"actor_location": {
"country_code": "XX"
},
"operation_type": "access",
"programmatic_access_type": "GitHub App server-to-server token"
}
Detection Rules #
YARA-L #
T1213Panther #
References #
repo.immutable_releases_settings_disabled
#Description
The setting for immutable releases was disabled for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000296,
"actor_id": 9000084,
"created_at": 1783612445753.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.immutable_releases_settings_disabled",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000297,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.immutable_releases_settings_enabled
#Description
The setting for immutable releases was enabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.pages_cname
#Description
A GitHub Pages custom domain was modified in a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"@timestamp": 1772492172155,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzNQ==",
"action": "repo.pages_cname",
"actor": "user",
"actor_id": 9000002,
"cname": "example.com",
"created_at": 1772492172155,
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAwNQAAAAAAAAA=",
"oauth_application_id": 9200001,
"old_cname": null,
"operation_type": "modify",
"programmatic_access_type": "OAuth access token",
"public_repo": true,
"repo": "user/example-repo",
"repo_id": 9100000002,
"request_access_security_header": null,
"request_id": "812A:273886:2655780:26DADAA:69A6158B",
"token_id": 9300000004,
"token_scopes": "admin:public_key,gist,read:org,repo,workflow",
"user": "user",
"user_agent": "GitHub CLI 2.87.3",
"user_id": 9000002,
"visibility": "public"
}
repo.pages_create
#Description
A GitHub Pages site was created.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000298,
"actor_id": 9000132,
"created_at": 1784899256670.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.pages_create",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000299,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.pages_destroy
#Description
A GitHub Pages site was deleted.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"@timestamp": 1772495640403,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzNw==",
"action": "repo.pages_destroy",
"actor": "user",
"actor_id": 9000002,
"created_at": 1772495640403,
"operation_type": "remove",
"public_repo": false,
"repo": "user/example-repo",
"repo_id": 9100000002,
"request_access_security_header": null,
"request_id": "D728:14548D:2797DF1:2824828:69A62308",
"user": "user",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
"user_id": 9000002,
"visibility": "private"
}
repo.pages_https_redirect_disabled
#Description
HTTPS redirects were disabled for a GitHub Pages site.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"@timestamp": 1772315857218,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzOA==",
"action": "repo.pages_https_redirect_disabled",
"actor": "user",
"actor_id": 9000002,
"created_at": 1772315857218,
"operation_type": "modify",
"public_repo": true,
"repo": "user/example-repo",
"repo_id": 9100000002,
"request_access_security_header": null,
"request_id": "D1E4:3F47F0:11992D4:157390B:69A364CE",
"user": "user",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
"user_id": 9000002,
"visibility": "public"
}
repo.pages_https_redirect_enabled
#Description
HTTPS redirects were enabled for a GitHub Pages site.
Documented on GitHub's enterprise audit log reference.
repo.pages_private
#Description
A GitHub Pages site visibility was changed to private.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000298,
"actor_id": 9000132,
"created_at": 1784899256739.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.pages_private",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000299,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.pages_public
#Description
A GitHub Pages site visibility was changed to public.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Sigma Example Audit Log Entry #
{
"@timestamp": 1772485305537,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDAzOQ==",
"action": "repo.pages_public",
"actor": "user",
"actor_id": 9000002,
"created_at": 1772485305537,
"operation_type": "modify",
"public_repo": true,
"repo": "user/example-repo",
"repo_id": 9100000002,
"request_access_security_header": null,
"request_id": "CD2C:3567FA:187CDCC:18CB04F:69A5FAB0",
"user": "user",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
"user_id": 9000002,
"visibility": "public"
}
Detection Rules #
Sigma #
T1567, T1567.001
repo.pages_soft_delete
#Description
A GitHub Pages site was soft-deleted because its owner's plan changed.
Documented on GitHub's enterprise audit log reference.
repo.pages_soft_delete_restore
#Description
A GitHub Pages site that was previously soft-deleted was restored.
Documented on GitHub's enterprise audit log reference.
repo.pages_source
#Description
A GitHub Pages source was modified.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000298,
"actor_id": 9000132,
"created_at": 1784899256732.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.pages_source",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000299,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.register_self_hosted_runner
#Description
A new self-hosted runner was registered.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Sigma event.action1 detection rule Elastic event.category1 detection rule Elastic Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000218,
"actor_id": 9000028,
"created_at": 1785241073436.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": true,
"actor_is_agent": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.register_self_hosted_runner",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000300,
"user_agent": "GitHubActionsRunner-linux-x64/2.335.1 CommitSHA/gggggggggggggggggggggggggggggggggggggggg Pid/40 CreationTime/2026-07-28T12%3A17%3A47.9481369Z (Runner)",
"actor_location": {
"country_code": "XX"
},
"operation_type": "create"
}
Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches repo.remove_self_hosted_runner Elastic #
T1195, T1195.001, T1195.002References #
repo.remove_actions_secret
#Description
A GitHub Actions secret was deleted for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000008,
"repo_id": 9000112,
"actor_id": 9000113,
"created_at": 1784292004129.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.remove_actions_secret",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000301,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.remove_actions_variable
#Description
A GitHub Actions variable was deleted for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000302,
"actor_id": 9000084,
"token_id": 9000303,
"created_at": 1782769218392.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"oauth_application_id": 9000044,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.remove_actions_variable",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000304,
"user_agent": "PyGithub/Python",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMg==",
"token_scopes": "gist,read:org,repo,workflow",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"external_identity_nameid": "user",
"programmatic_access_type": "OAuth access token",
"external_identity_username": "user"
}
References #
repo.remove_integration_secret
#Description
A Codespaces or Dependabot secret was deleted for a repository.
Documented on GitHub's enterprise audit log reference.
repo.remove_member
#Description
A collaborator was removed from a repository.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000274,
"user_id": 9000285,
"actor_id": 9000002,
"created_at": 1784578092176.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"user": "user",
"actor": "user",
"action": "repo.remove_member",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000305,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
T1195↳ also matches repo.add_member References #
repo.remove_self_hosted_runner
#Description
A self-hosted runner was removed.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Sigma Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000306,
"actor_id": 9000307,
"created_at": 1784237864073.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": true,
"actor_is_agent": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.remove_self_hosted_runner",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000308,
"user_agent": "go-github/v84.0.0",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyMw==",
"actor_location": {
"country_code": "XX"
},
"operation_type": "remove",
"programmatic_access_type": "GitHub App server-to-server token"
}
Detection Rules #
Sigma #
T1078, T1078.004, T1213, T1213.003, T1526↳ also matches repo.register_self_hosted_runner References #
repo.remove_topic
#Description
A topic was removed from a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000309,
"user_id": 9000182,
"created_at": 1782117787224.0,
"business_id": 9000005,
"public_repo": false,
"org": "example-org",
"repo": "user/example-repo",
"user": "user",
"topic": "example-label-117",
"action": "repo.remove_topic",
"business": "example-business",
"operation_type": "remove"
}
References #
repo.rename
#Description
A repository was renamed.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000310,
"actor_id": 9000311,
"created_at": 1783664367273.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.rename",
"actor_ip": "ip-redacted",
"business": "example-business",
"old_name": "example-repo",
"request_id": 9000312,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.rename_branch
#Description
A branch was renamed.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000313,
"actor_id": 9000314,
"created_at": 1785161728370.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"default_branch": true,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.rename_branch",
"actor_ip": "ip-redacted",
"business": "example-business",
"new_branch": "main",
"old_branch": "master",
"request_id": 9000315,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.restore
#Documented on GitHub's enterprise audit log reference.
repo.self_hosted_runner_offline
#Description
The runner application was stopped. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.
Documented on GitHub's enterprise audit log reference.
repo.self_hosted_runner_online
#Description
The runner application was started. This event is not available in the web interface, only via the REST API, audit log streaming, or JSON/CSV exports.
Documented on GitHub's enterprise audit log reference.
repo.self_hosted_runner_updated
#Description
The runner application was updated. This event is not included in the JSON/CSV export.
Documented on GitHub's enterprise audit log reference.
repo.set_actions_cache_retention_policy
#Description
The cache retention policy for GitHub Actions was set for a repository.
Documented on GitHub's enterprise audit log reference.
repo.set_actions_cache_storage_policy
#Description
The cache storage policy for GitHub Actions was set for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000268,
"actor_id": 9000047,
"created_at": 1780598516273.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.set_actions_cache_storage_policy",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000316,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.set_actions_fork_pr_approvals_policy
#Description
The setting for requiring approvals for workflows from public forks was changed for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"@timestamp": 1772318151374,
"_document_id": "U1lOX0RPQ18wMDAwMDAwMDAwMDA0NA==",
"action": "repo.set_actions_fork_pr_approvals_policy",
"actor": "user",
"actor_id": 9000002,
"created_at": 1772318151374,
"operation_type": "modify",
"policy": "ALL_OUTSIDE_COLLABORATORS",
"public_repo": true,
"repo": "user/example-repo",
"repo_id": 9100000002,
"request_access_security_header": null,
"request_id": "D334:209D2E:13C165B:17CCC73:69A36DC7",
"user": "user",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0",
"user_id": 9000002,
"visibility": "public"
}
repo.set_actions_private_fork_pr_approvals_policy
#Description
The policy for requiring approval for fork pull request workflows from collaborators without write access to private repos was changed for a repository.
Documented on GitHub's enterprise audit log reference.
repo.set_actions_retention_limit
#Description
The retention period for GitHub Actions artifacts and logs in a repository was changed.
Documented on GitHub's enterprise audit log reference.
repo.set_default_workflow_permissions
#Description
The default permissions granted to the GITHUB_TOKEN when running workflows were changed for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000317,
"actor_id": 9000068,
"created_at": 1781642275441.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.set_default_workflow_permissions",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000318,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "internal",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.set_fork_pr_workflows_policy
#Description
Triggered when the policy for workflows on private repository forks is changed.
Documented on GitHub's enterprise audit log reference.
repo.set_workflow_permission_can_approve_pr
#Description
The policy for allowing GitHub Actions to create and approve pull requests was changed for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000317,
"actor_id": 9000068,
"created_at": 1781642275459.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.set_workflow_permission_can_approve_pr",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000318,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "internal",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.staff_unlock
#Description
An enterprise owner or GitHub staff (with permission from a repository administrator) temporarily unlocked the repository.
Documented on GitHub's enterprise audit log reference.
repo.temporary_access_granted
#Description
Temporary access was enabled for a repository.
Documented on GitHub's enterprise audit log reference.
repo.transfer
#Description
A user accepted a request to receive a transferred repository.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000274,
"actor_id": 9000047,
"created_at": 1784578093901.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"owner": "example-org-1",
"action": "repo.transfer",
"actor_ip": "ip-redacted",
"business": "example-business",
"old_user": "example-business-1",
"repo_was": "example-business-1/example-repo-181",
"request_id": 9000305,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "transfer",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Panther #
References #
repo.transfer_outgoing
#Description
A repository was transferred to another repository network.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action2 detection rules Panther, Sigma Example Audit Log Entry #
{
"org_id": 9000008,
"repo_id": 9000046,
"actor_id": 9000047,
"created_at": 1784577551724.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.transfer_outgoing",
"new_nwo": "example-org-1/example-repo-100",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000049,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "transfer",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Sigma #
T1020, T1537YARA-L #
Panther #
References #
repo.transfer_start
#Description
A user sent a request to transfer a repository to another user or organization.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Panther Detection Rules #
Panther #
repo.unarchived
#Description
A repository was unarchived.
Documented on GitHub's enterprise audit log reference. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. The Detection Fields above are rule-derived rather than a complete schema: a sampled record can carry fewer keys than documented, and can carry keys GitHub does not document. See the audit log event model for what determines which fields a given record carries. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors action1 detection rule Sigma Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000279,
"actor_id": 9000229,
"created_at": 1783958357712.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.unarchived",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000319,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
Detection Rules #
Sigma #
References #
repo.update_actions_access_settings
#Description
The setting to control how a repository was used by GitHub Actions workflows in other repositories was changed.
Documented on GitHub's enterprise audit log reference.
repo.update_actions_secret
#Description
A GitHub Actions secret was updated for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000008,
"repo_id": 9000320,
"actor_id": 9000321,
"created_at": 1784810815510.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.update_actions_secret",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000322,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.update_actions_settings
#Description
A repository administrator changed GitHub Actions policy settings for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000323,
"actor_id": 9000055,
"token_id": 9000324,
"created_at": 1782765406126.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"updated_access_policy": true,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.update_actions_settings",
"actor_ip": "ip-redacted",
"business": "example-business",
"new_policy": "all",
"old_policy": "none",
"request_id": 9000325,
"user_agent": "GitHub CLI 2.45.0",
"visibility": "private",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyNA==",
"token_scopes": "admin:enterprise,admin:gpg_key,admin:org,admin:org_hook,admin:public_key,admin:repo_hook,admin:ssh_signing_key,audit_log,codespace,copilot,delete:packages,delete_repo,gist,notifications,project,repo,user,workflow,write:discussion,write:network_configurations,write:packages",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"programmatic_access_type": "Personal access token (classic)",
"external_identity_username": "user"
}
References #
repo.update_actions_variable
#Description
A GitHub Actions variable was updated for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000326,
"actor_id": 9000155,
"created_at": 1781722421899.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.update_actions_variable",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000327,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.update_default_branch
#Description
The default branch for a repository was changed.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000313,
"actor_id": 9000314,
"created_at": 1785161727276.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.update_default_branch",
"changes": {
"default_branch": "main",
"old_default_branch": "master"
},
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000315,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:152.0) Gecko/20100101 Firefox/152.0",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #
repo.update_integration_secret
#Description
A Codespaces or Dependabot secret was updated for a repository.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000097,
"repo_id": 9000328,
"actor_id": 9000329,
"created_at": 1783987254324.0,
"business_id": 9000005,
"public_repo": true,
"actor_is_bot": true,
"actor_is_agent": false,
"key": "DEPLOY_SYNTHETIC",
"org": "example-org",
"repo": "user/example-repo",
"actor": "user",
"action": "repo.update_integration_secret",
"business": "example-business",
"request_id": 9000330,
"user_agent": "Octokit Ruby Gem 10.0.0",
"integration": "example-label-118",
"hashed_token": "U1lOVEhFVElDX1RPS0VOX0hBU0hfMDAyNQ==",
"operation_type": "modify",
"programmatic_access_type": "GitHub App server-to-server token"
}
References #
repo.update_member
#Description
A user's permission to a repository was changed.
Documented on GitHub's enterprise audit log reference.Example Audit Log Entry #
{
"org_id": 9000002,
"repo_id": 9000331,
"user_id": 9000332,
"actor_id": 9000333,
"created_at": 1784538009284.0,
"business_id": 9000005,
"public_repo": false,
"actor_is_bot": false,
"org": "example-org",
"repo": "user/example-repo",
"user": "user",
"actor": "user",
"action": "repo.update_member",
"actor_ip": "ip-redacted",
"business": "example-business",
"request_id": 9000334,
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ip-redacted Safari/537.36",
"visibility": "private",
"actor_location": {
"country_code": "XX"
},
"operation_type": "modify",
"old_permissions": {
"admin": false,
"maintain": false,
"pull": true,
"push": true,
"triage": true
},
"new_repo_permission": "read",
"old_repo_permission": "write",
"external_identity_nameid": "user",
"external_identity_username": "user"
}
References #