A security-log entry can show a sign-in, authorization or account-setting change, but a single unfamiliar location is not proof of an intruder. VPNs, browser changes and legitimate tools can generate surprising entries. The event category, timestamp and related token or repository are more useful than a city label. GitHub lets personal-account owners review and export their security log; use it as a timeline for containment, not as a complete record of everything an attacker viewed.
Before you start
Use a trusted session and preserve the event details without publishing them. Know the recent work you and your automation performed. If the account belongs to an organization, also tell the organization security owner because its audit log and app installations may hold additional evidence.Do it step by step
- Open GitHub Settings, Security log and select the relevant timeframe. Filter or search for the event action and note the precise timestamp, actor, repository and token information shown. Export the log if a structured copy is needed for an incident review.
- Compare the event with your known device, browser, VPN and CI schedule. Check View and manage sessions for an unexplained login. Avoid dismissing a suspicious token event merely because its location resembles your own cloud provider.
- Inspect authorized OAuth apps, GitHub Apps and personal access tokens for a new or expanded grant. Revoke what you cannot explain and record the app name or token metadata before removing it.
- Review SSH and deploy keys, repository collaborators, new commits, releases and workflow runs around the same time. A repository change may be the consequence you need to contain, while a session row alone is only an access clue.
- If compromise remains plausible, revoke credentials or sessions using GitHub's official controls, change the password, secure your email and check 2FA methods. Rotate exposed repository secrets and coordinate with organization owners if shared resources were affected.
- Document the sequence of evidence and actions, then monitor for a repeat. Test a legitimate automation after revoking its token so an emergency security step does not silently halt a needed release.