<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GitHub Forensics — Blog</title>
    <link>https://www.githubforensics.com/de/blog</link>
    <description>Latest from Blog</description>
    <language>de</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:41:49 GMT</lastBuildDate>
    <atom:link href="https://www.githubforensics.com/de/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Grenzen des GitHub-Audit-Logs: Aufbewahrung, Lücken, Pläne</title>
      <link>https://www.githubforensics.com/de/blog/github-audit-log-limitations</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/github-audit-log-limitations</guid>
      <description>Was das GitHub-Audit-Log nicht erfasst: 180 bzw. 7 Tage Aufbewahrung, Plangrenzen für API und Git-Events, verborgene IPs, keine Dateiinhalte, kein Secret-Lesen.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub-Supply-Chain-Angriff untersuchen: ein Fallbeispiel</title>
      <link>https://www.githubforensics.com/de/blog/github-supply-chain-attack-investigation</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/github-supply-chain-attack-investigation</guid>
      <description>Ein fiktiver Supply-Chain-Angriff auf GitHub, durchgehend untersucht: gestohlenes PAT, 38 Repos geklont, AWS-Keys per Workflow geleakt, Branch-Schutz entfernt.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Geleakte Cloud-Keys in GitHub Actions: weiter in die Cloud</title>
      <link>https://www.githubforensics.com/de/blog/leaked-cloud-keys-github-actions</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/leaked-cloud-keys-github-actions</guid>
      <description>AWS-, Google-Cloud- oder Azure-Keys aus GitHub Actions oder einem Repo geleakt: Key sperren, Nutzung in Cloud-Audit-Logs verfolgen, Keys durch OIDC ersetzen.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Branch Protection deaktiviert? GitHub-Rulesets prüfen</title>
      <link>https://www.githubforensics.com/de/blog/branch-protection-ruleset-tampering</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/branch-protection-ruleset-tampering</guid>
      <description>Manipulierte Branch Protection oder Rulesets in GitHub untersuchen: protected_branch.destroy, Ruleset-Änderungen, Admin-Overrides, Umgebungen und neue Commits.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Übernahme einer GitHub-Organisation: Owner, 2FA, SSO</title>
      <link>https://www.githubforensics.com/de/blog/github-organization-takeover</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/github-organization-takeover</guid>
      <description>Anzeichen für die Übernahme einer GitHub-Organisation im Audit-Log: neue Owner, 2FA-Pflicht aus, SAML-SSO geändert, IP-Zulassungsliste aus, Streaming entfernt.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Self-hosted Runner Sicherheit: Forensik für GitHub Actions</title>
      <link>https://www.githubforensics.com/de/blog/self-hosted-runner-security</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/self-hosted-runner-security</guid>
      <description>Fremde oder kompromittierte Self-hosted Runner in GitHub: relevante Audit-Log-Ereignisse, Spuren in _diag auf dem Host, Umfang bestimmen, Runner neu aufbauen.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub-Actions-Secrets geleakt: Exfiltration untersuchen</title>
      <link>https://www.githubforensics.com/de/blog/github-actions-secrets-leak</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/github-actions-secrets-leak</guid>
      <description>Wie GitHub-Actions-Secrets trotz ***-Maskierung leaken: manipulierte Workflows, neue Branches, kodierte Ausgaben, fremde Actions – und welche Beweise zählen.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub: Repository-Exfiltration und Massen-Klonen erkennen</title>
      <link>https://www.githubforensics.com/de/blog/github-repository-exfiltration</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/github-repository-exfiltration</guid>
      <description>Quellcode-Diebstahl im GitHub-Audit-Log finden: git.clone-Häufungen, ZIP-Downloads, öffentlich gemachte oder übertragene Repos, Forks und ihre Spuren.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub-Token geleakt: Sofortmaßnahmen und Untersuchung</title>
      <link>https://www.githubforensics.com/de/blog/leaked-github-token</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/leaked-github-token</guid>
      <description>GitHub-PAT oder OAuth-Token geleakt? Widerrufen, hashed_token im Audit-Log finden, neue IPs, Länder und Klone prüfen und klären, worauf das Token zugriff.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub-Audit-Log-Analyse: Schritt für Schritt im Browser</title>
      <link>https://www.githubforensics.com/de/blog/github-audit-log-analysis</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/github-audit-log-analysis</guid>
      <description>GitHub-Audit-Log-Exporte offline analysieren: JSON, Git-Events und Actions-Protokolle ablegen, Urteil lesen, Befunde sichten, nach Token und IP pivotieren.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub-Audit-Log exportieren: UI, API und Streaming</title>
      <link>https://www.githubforensics.com/de/blog/export-github-audit-log</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/export-github-audit-log</guid>
      <description>GitHub-Audit-Log für die Forensik exportieren: JSON/CSV aus der UI, REST-API mit include=all, Streaming, Git-Events und Actions-Protokolle samt ihren Grenzen.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub-Organisation kompromittiert? So reagieren Sie</title>
      <link>https://www.githubforensics.com/de/blog/github-organization-compromised</link>
      <guid isPermaLink="true">https://www.githubforensics.com/de/blog/github-organization-compromised</guid>
      <description>GitHub-Organisation kompromittiert? Audit-Log sichern, Tokens und Workflows eindämmen, Umfang mit Git-Events bestimmen und dann in die Cloud weiterermitteln.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>