Observed arrival · 2026-09-28
GitHub Forensics: investigating a compromised organization
A browser-based tool that analyzes GitHub audit logs and related files to produce a compromise verdict, incident timeline, and remediation checklist.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- GitHub organization owners and incident responders
- Worth noticing
- Its collection guide distinguishes organization audit exports from Enterprise Cloud API access and notes a 180-day query limit.
Field notes
The collection guide walks through exporting organization audit logs in the GitHub interface and using the GitHub CLI for paginated API results. It also calls out a platform constraint: the audit-log API is unavailable on Free and Team plans, while the documented query can reach up to 180 days back. The sample data is explicitly fictional, depicting a stolen token replayed from a VPS.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue