GitHub user blocked from accessing organization repositories

github-telemetry

Classification:

attack

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when a GitHub user has been blocked from accessing organization repositories.

Strategy

This rule monitors GitHub audit logs for when a GitHub user has been blocked from accessing organization repositories. Organization owners and moderators can block anyone who is not a member of the organization from collaborating on the organization’s repositories.

Triage and response

  1. Determine if the change taken by {{@github.actor}} is authorized.
  2. If the change was not authorized or was unexpected, begin your organization’s incident response process and investigate.