M ManySignal
MS
GH
Integration

Github Integration

Code repository security events and secret scanning alerts in your SOC.

What this integration does

GitHub meets agentic SOC

GitHub is where code lives — and where attackers look for secrets, misconfigured Actions workflows, and supply chain injection points. ManySignal ingests GitHub Audit Log events, Secret Scanning alerts, Code Scanning alerts, and Advanced Security findings to detect credential leaks, branch protection bypasses, and repository tampering.

Organisation Audit Log ingestion for admin and repo events

Secret Scanning alert ingestion for leaked credentials

Code Scanning (CodeQL) alert ingestion

Data collected

  • GitHub Audit Log events (org, team, repo, webhook)
  • Secret Scanning alerts with secret type and location
  • Code Scanning alerts with rule, severity, and CWE
  • Dependabot alerts for vulnerable dependencies

Actions supported

  • Revoke GitHub personal access token
  • Suspend GitHub user from organisation
  • Enable branch protection rule on repository
  • Create GitHub issue for remediation tracking
  • Request pull request review from security team

Getting started

Set up in minutes

  1. 1

    Create a GitHub App

  2. 2

    Install the GitHub App

  3. 3

    Configure in ManySignal

  4. 4

    Enable detection rules

Github Integration: frequently asked questions

Is GitHub Advanced Security required?

Secret Scanning and Code Scanning require GitHub Advanced Security (available in GitHub Enterprise Cloud or GitHub Enterprise Server, or for public repositories for free). Audit Log ingestion works with all GitHub Enterprise plans.

Can ManySignal detect secrets that were already revoked?

ManySignal captures Secret Scanning alerts as they arrive, including alerts for secrets that have been auto-revoked by GitHub's push protection. The event is logged even if the secret is already invalidated.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.