Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,46 @@ contentType: how-tos
category:
- Monitor and audit your enterprise
---
{% data reusables.audit_log.retention-periods %}

{% ifversion ghec %}

There are several ways to access and retain audit log data for your enterprise:

* **Web interface**: View recent activity in your enterprise settings. See [Viewing the enterprise's audit log via the web interface](#viewing-the-enterprises-audit-log-via-the-web-interface).
* **JSON/CSV exports**: Download a file of audit log activity. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/exporting-audit-log-activity-for-your-enterprise).
* **REST API endpoint**: Query audit log events programmatically. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/using-the-audit-log-api-for-your-enterprise).
* **Streaming to an external system**: Deliver events continuously to a system that your incident responders can access and query. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise).

Each method exposes a different subset of your audit log data. For the full list of events, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise).

## Audit log data available by access method

{% data reusables.audit_log.events-data-retention-enterprise %}

For enterprises that use {% data variables.product.prodname_emus %}, the enterprise audit log also includes user events. For a list of these user events, see [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/security-log-events).

To retain Git events beyond their availability in the audit log, save them to external storage before they expire. Configure audit log streaming in advance to collect events continuously.

Git event exports do not include events initiated through the web interface or the REST or GraphQL APIs. For example, when someone merges a pull request in the web interface, the resulting push to the base branch is missing from the export.

`api.request` events are available only in streamed enterprise audit logs, and only when the option to stream API request events has been enabled. For more information, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#enabling-audit-log-streaming-of-api-requests).

> [!IMPORTANT]
> {% data reusables.audit_log.streaming-not-retroactive %}

## Preparing for an incident response

Enable enterprise audit log streaming, API request event streaming, and source IP address disclosure to prepare for incident response. Without all three features enabled, responders will have critical visibility gaps when investigating incidents affecting your enterprise or its organizations. Set an appropriate retention period for the streamed logs and ensure incident responders can access them.

For setup instructions, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming), [Enabling audit log streaming of API requests](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#enabling-audit-log-streaming-of-api-requests), and [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/displaying-ip-addresses-in-the-audit-log-for-your-enterprise).

{% data reusables.support.security-incident-expectations %}

{% endif %}

## Viewing the enterprise's audit log via the web interface

{% data reusables.audit_log.retention-periods %}
{% data reusables.enterprise-accounts.access-enterprise %}
{% data reusables.enterprise-accounts.settings-tab %}
{% data reusables.enterprise-accounts.audit-log-tab %}
Original file line number Diff line number Diff line change
Expand Up @@ -164,7 +164,7 @@ You can view all open alerts, and you can reopen alerts that have been previousl

## Reviewing the audit logs for {% data variables.product.prodname_dependabot_alerts %}

When a member of your organization {% ifversion not fpt %}or enterprise {% endif %}performs an action related to {% data variables.product.prodname_dependabot_alerts %}, you can review the actions in the audit log. For more information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log){% ifversion not fpt %} and [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/accessing-the-audit-log-for-your-enterprise).{% else %}.{% endif %}
When a member of your organization {% ifversion not fpt %}or enterprise {% endif %}performs an action related to {% data variables.product.prodname_dependabot_alerts %}, you can review the actions in the audit log. For more information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-organizations-audit-log-via-the-web-interface){% ifversion not fpt %} and [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/accessing-the-audit-log-for-your-enterprise).{% else %}.{% endif %}

![Screenshot of the audit log showing Dependabot alerts.](/assets/images/help/dependabot/audit-log-ui-dependabot-alert.png)

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ Read access to the repository.

* [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise)
* [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/audit-log-events-for-your-organization)
* [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/reviewing-your-security-log)
* [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/security-log-events){% ifversion ghec %}
* [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/identifying-audit-log-events-performed-by-an-access-token){% endif %}

Expand Down Expand Up @@ -147,6 +148,7 @@ Read access to the repository.

* [AUTOTITLE](/code-security/concepts/security-at-scale/security-overview)
* [AUTOTITLE](/code-security/how-tos/view-and-interpret-data/analyze-organization-data/viewing-security-insights)
* [AUTOTITLE](/code-security/how-tos/view-and-interpret-data/analyze-organization-data/find-insecure-repositories)

### Notes and limitations

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,10 +27,19 @@ These controls are critical for incident response, compliance, and operational t

### Audit log streaming

You should stream the enterprise audit logs to a Security Information and Event Management (SIEM) system. This keeps a copy of your audit log data (including both audit events and Git events) in a system where you can run complex queries across large volumes of data and retain data beyond default retention periods.
You should stream the enterprise audit logs, including API request events, to a Security Information and Event Management (SIEM) system. This keeps a copy of your audit log data (including web, Git and API events) in a system where you can run complex queries across large volumes of data and retain data beyond default retention periods.

> [!IMPORTANT]
> {% data reusables.audit_log.streaming-not-retroactive %}

This is critical in an incident because some high-value events are not visible in the {% data variables.product.github %} audit log web UI, and logs are only available for a limited time unless you export and retain them externally.

{% ifversion ghec %}

To compare event availability and retention across access methods, see [Audit log data available by access method](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/accessing-the-audit-log-for-your-enterprise#audit-log-data-available-by-access-method).

{% endif %}

With streamed logs, enterprise and organization owners can independently investigate activity from users, apps, tokens, and SSH keys, instead of depending on ad hoc data collection during an active response.

To set up audit log streaming, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise).
Expand All @@ -53,9 +62,9 @@ Enterprises on {% data variables.product.prodname_ghe_cloud %} can enable IP add

### Retain identity provider logs

If your enterprise uses SAML or OIDC authentication, adopt a similar retention strategy for your IdP logs.
If your enterprise or organizations use SAML or OIDC authentication, adopt a similar retention strategy for your identity provider (IdP) logs.

Retained IdP logs help you investigate authentication activity and review provisioning and deprovisioning events over longer time windows, including incidents that unfold over months.
Retained IdP logs help you investigate authentication activity and review provisioning, deprovisioning, and group membership changes over longer time windows. This is especially important if you use SCIM provisioning or need to investigate activity from several months ago.

## Familiarize yourself with tooling, limitations and common investigation areas

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,12 +23,13 @@ This guide walks you through how to respond to a security incident, outlining th

### Prerequisites

Ideally, you have **audit log streaming** and **source IP address visibility** already enabled for the enterprise (streaming the data to a security information and event management (SIEM) system) and you have access to that data. See [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise).
Investigating and responding to an incident is self-service. Before an incident occurs, enterprise owners should enable enterprise audit log streaming, API request event streaming, and source IP address disclosure. Without all three features enabled at the enterprise level, responders will have critical visibility gaps when investigating incidents affecting the enterprise or its organizations. Enterprise owners should also set an appropriate retention period for the streamed logs and ensure incident responders can access them. See [AUTOTITLE](/code-security/tutorials/secure-your-organization/prepare-for-a-security-incident#set-up-critical-tools-in-advance).

### Throughout your response

As you progress through your response, make sure that you:
* **Preserve evidence**: Take screenshots of suspicious activity, export logs or query results, and save copies of affected files or code before cleanup.

* **Capture available evidence**: Take screenshots of suspicious activity, export logs or query results while they are available, and save copies of affected files or code before cleanup. Opening a support ticket does not preserve logs or extend their retention period. {% ifversion ghec %}For information about {% data variables.contact.github_support %}'s role, see [AUTOTITLE](/support/learning-about-github-support/understanding-how-github-support-can-help-during-a-security-incident).{% endif %}
* **Keep a record**: Document your findings (for example, times, dates, Indicators of Compromise (IoCs), repositories affected) and record each decision you take.
* **Communicate**: Notify relevant stakeholders (such as security leads and engineering managers, as well as legal and privacy teams if sensitive data is at risk) and keep them updated.

Expand Down Expand Up @@ -74,6 +75,7 @@ The following {% data variables.product.github %} tools and surfaces can help.
For details on each tool, see [AUTOTITLE](/code-security/reference/security-incident-response/investigation-tools).

The validation phase can be **quick**:

* Aim to gather enough evidence to determine whether the signal is likely to be a **real** and **active** threat.
* If you can't quickly rule out the signal as a false positive, assume it's real.
* Deep investigation can be performed later.
Expand Down Expand Up @@ -120,6 +122,7 @@ For exposed or exploited credentials, the most immediate action you can take is
There are additional options for blocking credential access. For a full list by credential type, see [AUTOTITLE](/organizations/managing-programmatic-access-to-your-organization/github-credential-types).

{% ifversion single_user_cred_revocation %}

* **Revoke or delete credentials for a specific user**

If you've identified a specific compromised account, enterprise or organization owners on {% data variables.product.prodname_ghe_cloud %} can revoke SSO authorizations for that individual user. For enterprises with {% data variables.product.prodname_emus %}, you can also delete credentials entirely. This is less disruptive than bulk actions while still containing the threat. See [AUTOTITLE](/enterprise-cloud@latest/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens#taking-action-against-individual-members).
Expand All @@ -129,6 +132,7 @@ For exposed or exploited credentials, the most immediate action you can take is
If the incident is limited to one credential type, such as {% data variables.product.pat_v1_plural %}, enterprise or organization owners can revoke SSO authorizations or delete credentials of that type only, across all members, using the {% data variables.product.github %} UI{% ifversion ghec %} or REST API{% endif %}. This targets the affected credential type without disrupting other credentials. See [AUTOTITLE](/enterprise-cloud@latest/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens#taking-action-against-a-specific-credential-type).

{% endif %}

* **Emergency actions (major incident)**

Enterprise{% ifversion single_user_cred_revocation %} and organization{% endif %} owners on {% data variables.product.prodname_ghe_cloud %} can take bulk emergency actions to lock down access across their enterprise{% ifversion single_user_cred_revocation %} or organization{% endif %}. For enterprises with {% data variables.product.prodname_emus %}, this includes **deleting all user tokens and keys**. These are high-impact actions that will break automations and should be reserved for major incidents. See [AUTOTITLE](/enterprise-cloud@latest/admin/managing-iam/respond-to-incidents).
Expand Down Expand Up @@ -162,9 +166,9 @@ To restrict access to the enterprise, organization or repository, there are seve
* **Stop malicious workflow runs**

If you suspect that a {% data variables.product.prodname_actions %} workflow or runner is being used as part of an active attack, you can take the following actions:
* Cancel in-progress workflow runs for an affected repository. See [AUTOTITLE](/actions/how-tos/manage-workflow-runs/cancel-a-workflow-run).
* Disable {% data variables.product.prodname_actions %} for an affected repository in an organization, or for a specific organization. See [AUTOTITLE](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization) (organization owners) and [AUTOTITLE](/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise) (enterprise administrators).
* Remove self-hosted runners. See [AUTOTITLE](/actions/how-tos/manage-runners/self-hosted-runners/remove-runners).
* Cancel in-progress workflow runs for an affected repository. See [AUTOTITLE](/actions/how-tos/manage-workflow-runs/cancel-a-workflow-run).
* Disable {% data variables.product.prodname_actions %} for an affected repository in an organization, or for a specific organization. See [AUTOTITLE](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization) (organization owners) and [AUTOTITLE](/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise) (enterprise administrators).
* Remove self-hosted runners. See [AUTOTITLE](/actions/how-tos/manage-runners/self-hosted-runners/remove-runners).

* **Disable webhooks**

Expand Down Expand Up @@ -214,6 +218,7 @@ Even if you're not certain a credential was compromised, rotate it if there's an
You will need to check for persistence mechanisms that the attacker may have established to maintain access even after your initial containment actions.

This includes, but isn't limited to, checking for things like:

* Suspicious or unfamiliar workflow files that may have been added or modified.
* New webhooks pointing to unfamiliar domains.
* New self-hosted runners.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ category:
- Manage codespaces for your organization
---

When any member of your organization performs an action related to {% data variables.product.prodname_github_codespaces %}, you can review the actions in the audit log. For information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log).
When any member of your organization performs an action related to {% data variables.product.prodname_github_codespaces %}, you can review the actions in the audit log. For information about accessing the log, see [AUTOTITLE](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#accessing-the-organizations-audit-log-via-the-web-interface).

![Screenshot of the "Audit log" page for an organization, showing the "Recent events" list.](/assets/images/help/codespaces/codespaces-audit-log-org.png)

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@ contentType: how-tos
category:
- Configure Copilot
- Manage Copilot for a team
docsTeamMetrics:
- ai-governance
---

With enterprise managed settings, you can centrally define and distribute configuration settings for {% data variables.product.prodname_copilot %} to supported clients. This ensures everyone works within the guardrails you define, with the option to specialize settings for different teams. For example, you can block agents from performing sensitive operations, install approved agent plugins, or ensure that sessions run in a sandbox.
Expand Down
Loading
Loading