LoFP LoFP / validate the multifactor authentication changes.

Techniques

Sample rules

Github Outside Collaborator Detected

Description

Detects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an owner removes an outside collaborator from an organization or when two-factor authentication is required in an organization and an outside collaborator does not use 2FA or disables 2FA.

Detection logic

condition: selection
selection:
  action:
  - org.remove_outside_collaborator
  - project.update_user_permission