GitHub Audit Log: Delete Actions for Codespaces, Environments, Projects, and Repositories

Alerts on GitHub audit log deletion actions for Codespaces, environments, projects, and repositories.

FreeReviewedSigma · Medium · v5
Product
github
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2023-01-19
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags GitHub audit log events where delete-style actions occur for Codespaces, environments, projects, or repositories. Such activity matters because attackers may remove or disrupt resources to affect availability, hide activity, or reduce forensic evidence. Detection relies on GitHub audit log telemetry that records the specific action names (codespaces.destroy, environment.delete, project.delete, repo.destroy) associated with an actor.

Related detections4 linkedT1213.003 — drag to rearrange
Bitbucket Audit: Full Data Export Triggered
Bitbucket Audit: Unauthorized Full Data Export Triggered (Data Pipeline)
GitHub Audit Log: Self-Hosted Runner Configuration Changes
GitHub Audit: Outside Collaborator Membership and Permission Changes
GitHub Audit Log: Delete Actions for Codespaces, Environments, Projects, and Repositories
Pivot detection · T1213.003 · 4 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.