LoFP LoFP / developers authorizing approved internal or vendor oauth apps. maintain an allowlist of expected application names and investigate first-time grants from unusual ips or user agents.

Techniques

Sample rules

GitHub OAuth Application Authorized

Description

Detects when a user authorizes a GitHub OAuth application. Stolen OAuth grants persist after password changes until revoked and can clone or ZIP private repositories. This is not a GitHub App installation (integration_installation.create).

Detection logic

from logs-github.audit-* metadata _id, _index, _version
| where
  event.module == "github" and data_stream.dataset == "github.audit"
    and event.action == "oauth_authorization.create"
| keep
    _id,
    _index,
    _version,
    @timestamp,
    event.action,
    user.name,
    github.org,
    github.repo,
    github.actor_ip,
    github.hashed_token,
    github.oauth_application_name,
    github.oauth_application_id,
    github.programmatic_access_type,
    github.user_agent,
    github.name