For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-q3r.md. A documentation index is available at /llms.txt.

GitHub user blocked from accessing organization repositories

Goal

Detect when a GitHub user has been blocked from accessing organization repositories.

Strategy

This rule monitors GitHub audit logs for when a GitHub user has been blocked from accessing organization repositories. Organization owners and moderators can block anyone who is not a member of the organization from collaborating on the organization’s repositories.

Triage and response

  1. Determine if the change taken by {{@github.actor}} is authorized.
  2. If the change was not authorized or was unexpected, begin your organization’s incident response process and investigate.