GitHub Actions Academy · Security Playbooks

Identity Compromise Playbook

Contain and recover from suspected credential or privileged-access compromise.

Objective: Protect identities, preserve evidence and restore trusted access safely.

Practical guidance

Detect and contain

01

Confirm indicators and affected identities

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Revoke active sessions and risky tokens

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Restrict privileged access paths

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

04

Preserve authentication and audit evidence

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

Practical guidance

Recover and improve

01

Reset credentials through a trusted channel

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

02

Review role assignments and consent grants

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

03

Validate conditional access and MFA coverage

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.

04

Record root cause, lessons and control actions

Apply this point to a real GitHub Actions Academy design, delivery or operational scenario and record the evidence used to validate the outcome.