Skip to main content
GitHub Team and Free organizations should use the GitHub integration, which collects the security events available through GitHub App webhooks.
The GitHub Enterprise Cloud integration imports organization audit events into Wirespeed. Events include web and Git activity, such as changes to organization membership, repositories, permissions, settings, and authentication. Wirespeed indexes actor IP addresses and usernames for investigation and threat detection.

Before you connect

  • Confirm the organization uses GitHub Enterprise Cloud, which is required for organization audit-log access.
  • Have a GitHub organization owner available to complete or approve the Wirespeed GitHub App installation.
  • Review and accept the App’s read-only Organization administration permission. The App cannot modify repositories, organization settings, members, or code.
  • For IP-based investigations and detections, enable source IP disclosure under Organization Settings → Logs → Audit log → Settings.

Connect GitHub Enterprise Cloud

  1. In Wirespeed, open Settings → Integrations and select GitHub Enterprise Cloud.
  2. Review these instructions, then select Integrate.
  3. In GitHub, choose the Enterprise Cloud organization you want to monitor.
  4. Review the requested read-only organization permission and install the Wirespeed GitHub App.
  5. Authorize the App when GitHub prompts you. GitHub returns you to Wirespeed when the connection is ready.
Repeat the connection flow for each organization that should be monitored.
Deleting the Wirespeed connection does not uninstall the GitHub App. To connect the same organization again, uninstall the App in GitHub (Organization Settings → GitHub Apps), then reconnect from Wirespeed so GitHub can run the OAuth install flow again.
Wirespeed uses the authorizing user’s short-lived GitHub token only to verify access to the selected installation. Polling uses a one-hour installation token that is regenerated automatically; the user’s token is not retained.

Data collection

The first sync imports up to seven days of available organization audit events. Later syncs resume from the latest successfully ingested event and include both web and Git events.
Source IP disclosure is disabled by default. Audit events are still ingested when it is disabled, but they do not include the actor IP address used by IP-based investigations and detections.
GitHub can return 403 or 404 when the organization is not on Enterprise Cloud or the App does not have Organization administration read permission. Wirespeed reports that state on the integration rather than collecting partial audit data.

Detections

Wirespeed includes starter managed detections for organization IP allow-list changes, owner-role assignments, SAML and two-factor requirement changes, and grants of personal access tokens, OAuth Apps, or GitHub Apps.