GitHub OAuth Application Authorized

Last updated 8 days ago on 2026-09-24
Created 8 days ago on 2026-09-24

About

Detects when a user authorizes a GitHub OAuth application. Stolen OAuth grants persist after password changes until revoked and can clone or ZIP private repositories. This is not a GitHub App installation (integration_installation.create).
Tags
Domain: CloudDomain: SaaSDomain: IdentityPlatform: GitHubProfile: BetaUse Case: Threat DetectionTactic: Credential AccessTactic: PersistenceThreat: OAuth App ConsentData Source: GithubData Source: GitHub Audit LogsRule Type: ESQLLanguage: esql
Severity
low
Risk Score
21
MITRE ATT&CK™

Persistence (TA0003)(external, opens in a new tab or window)

Credential Access (TA0006)(external, opens in a new tab or window)

False Positive Examples
Developers authorizing approved internal or vendor OAuth apps. Maintain an allowlist of expected application names and investigate first-time grants from unusual IPs or user agents.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Integration Pack
Prebuilt Security Detection Rules
Related Integrations

github(external, opens in a new tab or window)

Query
text code block:
from logs-github.audit-* metadata _id, _index, _version | where event.module == "github" and data_stream.dataset == "github.audit" and event.action == "oauth_authorization.create" | keep _id, _index, _version, @timestamp, event.action, user.name, github.org, github.repo, github.actor_ip, github.hashed_token, github.oauth_application_name, github.oauth_application_id, github.programmatic_access_type, github.user_agent, github.name

Install detection rules in Elastic Security

Detect GitHub OAuth Application Authorized in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).