GitHub Pages repository site changed to public (repo.pages_public audit event)

Flags when a GitHub repository’s Pages site visibility is changed to public in the audit log.

FreeReviewedSigma · Low · v5
Product
github
Service
audit
Author
Ivan Saakov (SigmaHQ), DRL 1.1
Published
2025-10-18
Updated
2026-07-31

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule flags GitHub audit log activity where a repository’s GitHub Pages site is set to public. Making a Pages site public can be part of legitimate publishing, but it also increases the risk of unintended exposure of repository content. The detection relies on the GitHub audit event action indicating the Pages visibility change.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.