elastic
medium
kql
GitHub UEBA - Multiple Alerts from a GitHub Account
This rule is part of the "GitHub UEBA - Unusual Activity from Account Pack", and leverages alert data to determine when
multiple alerts are executed by the same user in a timespan of one hour. Analysts can use this to prioritize triage and
response, as these alerts are a higher indicator of compromised user accounts or PATs.