GitHub enterprise or organization recovery codes activity
이 페이지는 아직 영어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다.Goal
Detect when a GitHub enterprise or organization recovery code has been interacted with by a user.
Strategy
This rule monitors GitHub audit logs for when a Github recovery code is generated, viewed, downloaded, or printed. Attackers may use recovery codes to establish an administrator account and allow persistent access to the Github organization.
Triage and response
- Determine if the action taken by
{{@github.actor}}
is expected and/or authorized. - If the change was not authorized or was unexpected, begin your organization’s incident response process and investigate.