Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
How GitHub Uses GitHub to Defend GitHub
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Scott J. Roberts
February 24, 2014
Technology
370
3
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
How GitHub Uses GitHub to Defend GitHub
A talk I gave for a closed conference right around RSA 2014.
Scott J. Roberts
February 24, 2014
More Decks by Scott J. Roberts
See All by Scott J. Roberts
LLM SATs FTW
sroberts
0
1.7k
STRAT - A System-Centric Approach to Cyber Resilience
sroberts
0
100
Tortured Responders Dept - Scott & Rebekah's Edition
sroberts
0
180
Skynet the CTI Intern: Building Effective Machine Augmented Intelligence
sroberts
0
210
DRIVING INTELLIGENCE WITH MITRE ATT&CK: LEVERAGING LIMITED RESOURCES TO BUILD AN EVOLVING THREAT REPOSITORY
sroberts
0
150
Exploring Threat Intelligence: Insights and Tools from Vertex Synapse
sroberts
0
150
Homemade Ramen & Threat Intelligence
sroberts
2
650
Introduction to Open Source Security Tools
sroberts
3
5.1k
Building Effective Threat Intelligence Sharing
sroberts
1
160
Other Decks in Technology
See All in Technology
AI時代に顧客へ最速で価値を 届けるための試行錯誤 〜「AI × マネジメント」領域におけるmentoのケース〜
posterkeisuke
0
110
AIオーケストレーションを活用した 開発ワークフローの設計と実践
bqnq
0
120
コスト最適化の「めんどくさい」を AWS FinOps Agent でチョット楽にする
classmethod_kaz
0
290
Redmine 7.0で私が開発した新機能の狙いと背景
vividtone
1
130
AIとペアプロを始める。人とのペアプロをやめる。ペアプロの良さを改めて知る。もっと好きになった。 / Rediscovering Pair Programming
honyanya
1
320
Adaptive Warehouse を今すぐ導入すべき理由と迷ったときの判断基準
__allllllllez__
0
140
2026/09/10 Spring_Bootから_Jakarta_EE_MicroProfileへの移行
megascus
0
280
ASTを使って影響範囲を特定する
nealle
0
140
Sigmaユーザーのための有用リソース一挙公開 & Sigmaで使えるMCP #sigma_ucj /useful-resources-for-sigma-computing-users-and-mcps-with-sigma
shinyaa31
0
170
TinyGo 開発サイクルを高速化する:Go で作るエミュレータ入門
zozotech
PRO
1
370
深夜のクラウド懺悔室 1:29:300 or 1:0:0
kazzpapa3
1
220
DEFCON_CHV_CTF_Write-up.pdf
bata_24
0
110
Featured
See All Featured
How Fast Is Fast Enough? [PerfNow 2025]
tammyeverts
3
880
Building a Modern Day E-commerce SEO Strategy
aleyda
45
9.2k
Why Mistakes Are the Best Teachers: Turning Failure into a Pathway for Growth
auna
0
260
Building Experiences: Design Systems, User Experience, and Full Site Editing
marktimemedia
0
600
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
35
2.8k
svc-hook: hooking system calls on ARM64 by binary rewriting
retrage
2
560
A Tale of Four Properties
chriscoyier
163
24k
Crafting Experiences
bethany
1
310
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.8k
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
380
The Language of Interfaces
destraynor
162
27k
Building AI with AI
inesmontani
PRO
1
1.2k
Transcript
! To Defend Scott J Roberts Bad Guy Catcher Uses
How
this isn’t a sales pitch… but it is about using
GitHub the product
Our Goals • Use current tools & paradigms • Fast
• Secure • Transparent to coworkers
We live on GitHub (shocking!) • Writing code • Writing
documentation • Having long running collaborative discussions • So why not incident response?
Our Incident Process • Create an incident name • Create
an incident branch • Apply the Incident Template • Open a Pull Request • “Run it down” • Finalize & Merge • it
Create an incident name • Two word names • First
word is “actor” - to the extent we know • Second word is the incident • Initials should be unique
Create an “Incident Branch”
Add Incident Template
Our Templates
Our Templates
Git Add, Commit, & Push
Open a Pull Request
Open a Pull Request
“Run it down”
“Run it down” • Using the Pull Request workflow for
IR: • Ties response directly to the code, such as fixes • Allows us to pull in relevant users & teams as necessary • Lets us categorize, organize, & track using Milestones, Labels, & States
Finalize and Merge
it • We share GitHub security incidents with all Hubbers
• This helps us with a few things: • Raising OpSec awareness • Identifying & developing new features • Building user trust
Quick Review 1. Create a branch 2. Add & fill
out template 3. Add, commit, & push 4. Open a Pull Request 5. “Run it down” 6. Finalize & Merge
Wake Up, Go T o War