heroui logo

GitHub OAuth Application Authorized

Elastic Detection Rules

View Source
Summary
Detects when a user authorizes a GitHub OAuth application via oauth_authorization.create in GitHub audit logs. A granted OAuth token can enable programmatic access to repositories, potentially allowing cloning or downloading private repositories until the token is revoked. This is distinct from installing a GitHub App (integration_installation.create). The rule surfaces key fields such as user.name, github.oauth_application_name and id, github.actor_ip, github.user_agent, github.programmatic_access_type, and github.hashed_token to support investigation and attribution. It supports triage by correlating with subsequent git.clone or repo.download_zip activity that uses the OAuth token, and helps identify persistence through credential access. The detection is designed for identity and cloud/SaaS monitoring around GitHub OAuth grants and tokens, enabling rapid response if the authorization was unauthorized or unauthorized scopes were requested.
Categories
  • Cloud
  • Web
  • Application
  • Identity Management
Data Sources
  • Web Credential
  • Logon Session
  • Cloud Service
  • Internet Scan
  • Certificate
  • File
  • Process
  • Module
  • Domain Name
ATT&CK Techniques
  • T1078
  • T1078.004
  • T1528
Created: 2026-09-24