Code & history
Malicious commits, rewritten history, branches, tags, releases, binaries, generated files, submodules, and visibility changes.
OPERATIONAL PLAYBOOK · IR-05
Preserve the record, stop active execution, find every persistence path, restore from trusted state, and prove remediation before normal development resumes.
Record investigation decisions and collect evidence before destructive remediation, except when an active path must be stopped immediately.
Malicious commits, rewritten history, branches, tags, releases, binaries, generated files, submodules, and visibility changes.
Workflow changes and runs, reusable workflows, action references, environments, artifacts, caches, deployments, and runners.
Manifest and lockfile changes, install scripts, registries, compromised packages, dependency confusion, and unpinned actions.
Repository, environment and organization secrets; PATs; SSH and deploy keys; app tokens; cloud, registry, signing, and CI credentials.
New webhooks, deploy keys, collaborators, teams, apps, OAuth grants, runners, branch bypasses, ruleset changes, and executables.
Published packages, releases, deployments, images, provenance, clones, forks, mirrors, and systems reachable by exposed credentials.
Revoke exploited credentials; disable malicious workflows, runners, webhooks, apps, deployments, refs, or packages.
Restore rules and access, remove unauthorized integrations, rebuild runners, audit dependencies, and reinstall trusted pinned versions.
Treat potentially exposed credentials as compromised, including signing, cloud, registry, CI, repository, environment, and organization secrets.
Control mapping: GitHub's official security incident response guidance and incident investigation areas. Feature availability depends on plan and pre-incident configuration.
AUTHORSHIP & REVIEW