GitHub MFA requirement disabled

Goal

Detect when a GitHub multi-factor authentication (MFA) requirement has been disabled.

Strategy

This rule monitors GitHub audit logs for when a GitHub MFA requirement has been disabled. The requirement for members to have two-factor authentication enabled to access an enterprise/organization was disabled. Attackers may may disable or modify MFA mechanisms to enable persistent access to compromised accounts.

Triage and response

  1. Determine if the change taken by {{@github.actor}} is authorized.
  2. If the change was not authorized or was unexpected, begin your organization’s incident response process and investigate.
PREVIEWING: joe.farro/djm/djm-732-rm-dd-api-ips-databricks-docs