GitHub Audit: Outside Collaborator Membership and Permission Changes

Alerts on GitHub audit events involving outside collaborators being removed or permission changes on projects.

FreeReviewedSigma · Medium · v5
Product
github
Service
audit
Author
Muhammad Faisal (@faisalusuf) (SigmaHQ), DRL 1.1
Published
2023-01-20
Updated
2026-07-31

ATT&CK techniques

Persistence → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags GitHub audit log events where an outside collaborator is removed or where a user’s project board permissions are updated. Such changes can be used to reduce access for defenders or alter project access to support persistence and data collection. The detection relies on GitHub audit events for collaborator removal and project permission updates, including the associated actor and organization/project context.

Related detections9 linkedT1098.001 — drag to rearrange
Suspicious MURKY PANDA Mail Permission Grant to Service Principal (via azure)
Suspicious MURKY PANDA Credential Addition to Entra ID Service Principal (via azure)
Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
Suspicious IAM Access Key Creation for Persistence (via cloudtrail)
Suspicious AWS Administrator Policy Attachment via CloudTrail (via aws)
Suspicious AWS Inline Policy Granting Full S3 Access
Suspicious GCP Service Account Key Creation for Persistence (via gcp.audit)
Malicious Credential Added to an Azure AD Application (via auditlogs)
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
GitHub Audit: Outside Collaborator Membership and Permission Changes
Pivot detection · T1098.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.