Skip to main content
Skip to content

Understanding how GitHub Support can help during a security incident

Understand what GitHub 支持 can and cannot do during a security incident, and find resources to investigate and respond.

About security incidents

A security incident is an event that could compromise your enterprise's accounts, code, or other data. Examples include compromised accounts, leaked credentials, unexpected access, or unauthorized changes.

Investigating and responding to an incident is self-service. Before an incident occurs, enable enterprise audit log streaming, API request event streaming, and source IP address disclosure. Retain the logs in storage that your incident responders can access.

重要

Audit log streaming only includes activity from the time you enable it. Enabling it during an incident will not recover earlier activity.

For guidance on preparing for and responding to an incident, see:

How GitHub 支持 can help

重要

When an incident occurs, follow your incident response procedures immediately. Focus first on containing the threat with actions appropriate to the incident, such as restricting access and revoking or rotating compromised credentials.

For enterprise-level containment options, see 锁定企业中的单点登录 and 在企业中撤销授权或删除凭据.

GitHub 支持 can answer questions about GitHub's features and the data available to you, so you can investigate and analyze the activity yourself. GitHub 支持 does not investigate or analyze on your behalf.

If you need guidance using these features or want to request a feature, see 创建支持工单.

GitHub 支持 handles all security-related matters in writing through support tickets.

No managed incident response service

GitHub 支持 does not join or lead your incident response process. To investigate and contain a threat, use GitHub's audit log, security, and access-management tools.

No log preservation

GitHub 支持 cannot fulfill requests to preserve logs or audit data, extend their retention periods, or place them on hold for your investigation. Opening a support ticket does not change how long data remains available. To retain data for an investigation, export it while it is available or configure audit log streaming in advance to storage you control.

Further reading