
Summary
Detects when a user authorizes a GitHub OAuth application via oauth_authorization.create in GitHub audit logs. A granted OAuth token can enable programmatic access to repositories, potentially allowing cloning or downloading private repositories until the token is revoked. This is distinct from installing a GitHub App (integration_installation.create). The rule surfaces key fields such as user.name, github.oauth_application_name and id, github.actor_ip, github.user_agent, github.programmatic_access_type, and github.hashed_token to support investigation and attribution. It supports triage by correlating with subsequent git.clone or repo.download_zip activity that uses the OAuth token, and helps identify persistence through credential access. The detection is designed for identity and cloud/SaaS monitoring around GitHub OAuth grants and tokens, enabling rapid response if the authorization was unauthorized or unauthorized scopes were requested.
Categories
- Cloud
- Web
- Application
- Identity Management
Data Sources
- Web Credential
- Logon Session
- Cloud Service
- Internet Scan
- Certificate
- File
- Process
- Module
- Domain Name
ATT&CK Techniques
- T1078
- T1078.004
- T1528
Created: 2026-09-24