Enterprise Audit Log Investigator

Run common saved searches against the GitHub enterprise audit log — Copilot policy changes, secret-scanning push-protection bypasses, SSO events, allowed-Actions list edits, content-exclusion changes. Each canonical search has a structured query (the `gh api`-equivalent of the audit log search syntax), the matching `action` types, expected normal volume, alert threshold, and what to do if results spike. Use during incident response (something changed and we need to know who/when), during quarterly audit prep, or proactively as part of a security-monitoring rhythm.

themarmack Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/enterprise-audit-log-investigator commit c432636a30

Frequently asked questions

npx skillmds@latest add themarmack/enterprise-audit-log-investigator