Skip to main content
Skip to content

Understanding how GitHub Support can help during a security incident

Understand what GitHub Support can and cannot do during a security incident, and find resources to investigate and respond.

About security incidents

A security incident is an event that could compromise your enterprise's accounts, code, or other data. Examples include compromised accounts, leaked credentials, unexpected access, or unauthorized changes.

Investigating and responding to an incident is self-service. Before an incident occurs, enable enterprise audit log streaming, API request event streaming, and source IP address disclosure. Retain the logs in storage that your incident responders can access.

Important

Audit log streaming only includes activity from the time you enable it. Enabling it during an incident will not recover earlier activity.

For guidance on preparing for and responding to an incident, see:

How GitHub Support can help

Important

When an incident occurs, follow your incident response procedures immediately. Focus first on containing the threat with actions appropriate to the incident, such as restricting access and revoking or rotating compromised credentials.

For enterprise-level containment options, see Locking down single sign-on in your enterprise and Revoking authorizations or deleting credentials in your enterprise.

GitHub Support can answer questions about GitHub's features and the data available to you, so you can investigate and analyze the activity yourself. GitHub Support does not investigate or analyze on your behalf.

If you need guidance using these features or want to request a feature, see Creating a support ticket.

GitHub Support handles all security-related matters in writing through support tickets.

No managed incident response service

GitHub Support does not join or lead your incident response process. To investigate and contain a threat, use GitHub's audit log, security, and access-management tools.

No log preservation

GitHub Support cannot fulfill requests to preserve logs or audit data, extend their retention periods, or place them on hold for your investigation. Opening a support ticket does not change how long data remains available. To retain data for an investigation, export it while it is available or configure audit log streaming in advance to storage you control.

Further reading