6 ms·
Does anyone know what to look for in the github audit logs, exactly?
by samcheng 4y ago
Does anyone know what to look for in the github audit logs, exactly?
- nomilk 4y agoTry here: https://github.com/settings/security-log https://github.com/settings/security-log
- captn3m0 4y agoDon’t think these logs mention the oauth application being used to access at all.
- samcheng 4y agoI used here: https://github.com/organizations/<ORG_NAME>/settings/audit-log https://github.com/organizations/<ORG_NAME>/settings/audit-l... ... but the real question is what would malicious activity look like, exactly?
- yeskia 4y agoI see a heap of "downloaded a zip of repository" but I suspect that's Heroku CI or other CI tool running.
- domh 4y agoYeah I see lots of the same. They seem to correspond with Heroku deploys? Anyone know if that happens when a valid heroku deploy occurs? Do they download a zip? I've reached out to Heroku support to ask.
- andrelaszlo 4y agoPlease let us know if you get any info from them! :)
- heartbreak 4y agoNormal Heroku usage doesn’t download a zip because it uses git directly, but I’ve seen plenty of CI tools download zips.
- domh 4y agoI thought as much. Maybe it is CircleCI then.
- all-the-lights 4y agoIncluding Heroku CI? We don't use an external CI tool (or really any other integrations except GH), but I do see these download logs.
- heartbreak 4y agoFor what it's worth, elsewhere in this comment section someone posted that Github Support says the zip downloads weren't related to this incident. Reading between the lines, the compromised repos were probably accessed using normal git clone actions.
- all-the-lights 4y agoThat was me who posted that :) seems unrelated, but still hoping to get that figured out anyway.
- all-the-lights 4y agoSame. Most belong to 1 member of our team, but a few belong to others on the team. They started happening about 6 months ago (unless logs only go back 6 mo). Would really like to figure out what these are. I asked GH, they said it’s not involved with this breach, and haven’t yet answered my next question (who/what is it?)
- janejeon 4y agoI believe OP was asking what to look out for within the security log, not how to look at the security log.
- gnyman 4y agoLast year when I looked into this there was no automated way to get this info; the normal audit log mentioned below does not contain any info about actions from oauth-ed applications afaik. If you email GitHub support they can pull out detailed logs from oauth app interactions from their internal tools. I would expect the GH security team to have relevant queries ready by now, maybe even do some proactive queries and start alerting anyone who had suspicious activity. (But this is just how I'd do it I have no special insight if they are doing this or something else).
- bongobingo1 4y agoTangentially, You can view your oauth linked services here https://github.com/settings/applications https://github.com/settings/applications