Microsoft Sentinel just gained support for GitHub continuous threat monitoring, which helps track potentially malicious events after ingesting GitHub enterprise repository logs.
See also: Microsoft Defender: Detects vulnerabilities in Android and iOS

Microsoft Sentinel (formerly known as Azure Sentinel) is the cloud-native SIEM (Security Information and Event Management) platform.
It uses artificial intelligence (AI) to analyze massive amounts of data, looking for potential threat actor activity in corporate environments.
See also: FTC investigates deal between Microsoft and Activision Blizzard
Microsoft Sentinel GitHub Threat Monitoring works only with GitHub enterprise licenses and comes with analysis rules to trigger alerts for suspicious events and a workbook for data visualization.

Alerts that will appear in the Microsoft Sentinel dashboard that are triggered by the new analytics rules include the following:
- Repository created: Every time a repository is created in the GitHub environment connected to the Microsoft Sentinel workspace.
- Repository destroyed: Whenever a repository is destroyed in the GitHub environment.
- A payment method was removed: whenever there is an action with the payment method configured for the GitHub repository.
- OAuth implementation: Every time a “client secret” is removed.
Using the workbook, security teams can track members added and removed from a GitHub repo, new repositories added, and how many times each repo was forked or cloned.
See also: Microsoft: Multi-stage phishing campaign exploits Azure AD
You can find detailed instructions on connecting your enterprise-licensed GitHub repository to your Microsoft Sentinel workspace in this Microsoft post.
Information source: bleepingcomputer.com
