Github Integration
Code repository security events and secret scanning alerts in your SOC.
What this integration does
GitHub meets agentic SOC
GitHub is where code lives — and where attackers look for secrets, misconfigured Actions workflows, and supply chain injection points. ManySignal ingests GitHub Audit Log events, Secret Scanning alerts, Code Scanning alerts, and Advanced Security findings to detect credential leaks, branch protection bypasses, and repository tampering.
Organisation Audit Log ingestion for admin and repo events
Secret Scanning alert ingestion for leaked credentials
Code Scanning (CodeQL) alert ingestion
Data collected
- GitHub Audit Log events (org, team, repo, webhook)
- Secret Scanning alerts with secret type and location
- Code Scanning alerts with rule, severity, and CWE
- Dependabot alerts for vulnerable dependencies
Actions supported
- Revoke GitHub personal access token
- Suspend GitHub user from organisation
- Enable branch protection rule on repository
- Create GitHub issue for remediation tracking
- Request pull request review from security team
Getting started
Set up in minutes
- 1
Create a GitHub App
- 2
Install the GitHub App
- 3
Configure in ManySignal
- 4
Enable detection rules
Github Integration: frequently asked questions
Is GitHub Advanced Security required?
Secret Scanning and Code Scanning require GitHub Advanced Security (available in GitHub Enterprise Cloud or GitHub Enterprise Server, or for public repositories for free). Audit Log ingestion works with all GitHub Enterprise plans.
Can ManySignal detect secrets that were already revoked?
ManySignal captures Secret Scanning alerts as they arrive, including alerts for secrets that have been auto-revoked by GitHub's push protection. The event is logged even if the secret is already invalidated.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.