Techniques
Sample rules
GitHub OAuth Application Authorized
- source: elastic
- technicques:
- T1078
- T1528
Description
Detects when a user authorizes a GitHub OAuth application. Stolen OAuth grants persist after password changes until revoked and can clone or ZIP private repositories. This is not a GitHub App installation (integration_installation.create).
Detection logic
from logs-github.audit-* metadata _id, _index, _version
| where
event.module == "github" and data_stream.dataset == "github.audit"
and event.action == "oauth_authorization.create"
| keep
_id,
_index,
_version,
@timestamp,
event.action,
user.name,
github.org,
github.repo,
github.actor_ip,
github.hashed_token,
github.oauth_application_name,
github.oauth_application_id,
github.programmatic_access_type,
github.user_agent,
github.name