GitHub Audit Log: New Organization Member Added or Invited

Alerts on GitHub org audit events where a member is added or invited to a new or existing organization.

FreeReviewedSigma · Informational · v5
Product
github
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2023-01-29
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags GitHub organization audit events where a user is added to an organization or invited as a new member. Attackers may abuse these actions to establish persistence or gain access by enrolling new accounts into a target org. It relies on GitHub audit log telemetry that records organization membership change actions such as org.add_member and org.invite_member.

Related detections4 linkedT1136.003 — drag to rearrange
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Suspicious AWS IAM User Creation Using Support Impersonation Name
M365 Exchange Add-FederatedDomain Success: New Federated Domain Created
AWS CloudTrail: ElastiCache Cache Security Group Created
GitHub Audit Log: New Organization Member Added or Invited
Pivot detection · T1136.003 · 4 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.