Unauthorized GitHub Personal Access Token Created by Emily Eaton
Alert Summary
On May 16, 2024, at 17:15:40 PST, a SIEM alert with ID siem_591204 was triggered due to the creation of a new personal access token in GitHub by emily.eaton@thisisarealcompany.com, which violated the policy of thisisarealcompany.com. The token, created from IP 66.91.103.212 in Salt Lake City, UT, included scopes such as repo, workflow, and read:org, and is associated with github_org_id 1184952. This "Credential Management" alert, linked to MITRE technique T1136, has a severity level of 4 and can be reviewed at siem.thisisarealcompany.com/alerts/591204.
Top Findings
Emily denied involvement in creating the token and uses a VPN.
Token scopes repo, workflow, read:org allow extensive access.
No evidence of token creation or access events in GitHub logs.
IP 66.91.103.212 is in Salt Lake City, UT.
Conclusion
The user emily.eaton@thisisarealcompany.com created a personal access token with the repo, workflow, and read:org scopes. This came from an IP address 66.91.103.212 in a location that was is not recognized indicates the alert may be associated with unauthorized action.
Pending Interview
emily.eaton@thisisarealcompany.com
On May 16, 2024 at 17:15:40 PST, was a personal access token created in GitHub for the account in question? If so, please describe why it was needed, why the scopes (repo, workflow, read:org) were chosen, and whether any VPN, proxy, or remote network was in use when it was generated.
Associated Entities
thisisarealcompany.comemily.eaton@thisisarealcompany.com66.91.103.212