Security1 distinct publisher2 min readPublished
Wiz CIRT's poster puts 88 percent of its customers on hosted version control, where Git read and write events age out in a week and the fix, streaming them somewhere else, often sits behind a higher license tier.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Do the subtraction on a realistic discovery lag. If a repository compromise surfaces 30 days after initial access, 23 of those days of Git read and write activity sit outside GitHub's default window [15]. What remains is the standard audit log, and Wiz's own framing is that standard audit logs do not capture all activity and that default retention limits severely restrict historical investigations [10]. The clone and fetch record, meaning the evidence of what an attacker actually pulled out of the repositories, is the part that expires first [3].
GitLab presents a different shape of the same problem. In a standard configuration, Git operations are never written to the database, so those events are unavailable no matter when the investigation opens, unless log streaming was configured in advance [4].
The API layer is thinner still. Wiz reports 88 percent of its customers on SaaS version control, where the raw API requests to the server are abstracted away from the tenant [5]. One of the four platforms in the poster lets an organisation log those requests, and only with explicit configuration plus streaming [6], which leaves three with no organisation-visible API log at all [16]. Wiz places early-stage discovery and enumeration in exactly that telemetry, ahead of any impact [7]. Whether you can see the reconnaissance phase is therefore settled by which vendor you signed with.
Two configuration items carry most of the weight in the readiness checklist. Streaming is the first, and Wiz notes it is frequently restricted to higher license tiers, which turns a telemetry decision into a procurement one [8]. Source IP capture is the second: GitHub does not expose actor IP addresses in audit logs unless the setting is enabled manually, and without it, tracing the origin of malicious activity gets significantly harder [9].
This is a single-source account, and worth reading as one. Wiz is describing platform defaults it also sells around, and its suggestion that these logs go to a cloud detection and response platform rather than a legacy SIEM is a product argument [13]. The retention and licensing claims themselves are checkable against each vendor's documentation, which is where anyone acting on this should confirm their own tier. The checklist behind them comes from Wiz CIRT casework across multiple supply chain attacks and targeted campaigns [12], and Wiz cites campaigns attributed to TeamPCP as an example of actors going after version control systems directly [11].
No patch cycle applies here. The remediation is a configuration change and a destination for the events, and its value is decided entirely by whether it was made before the intrusion rather than after [14].
Ranked by verification strength, evidence, and original report placement.
Wiz CIRT created a Version Control Digital Forensics and Incident Response poster summarising available logs, a pre-incident configuration checklist, and specific audit event names to hunt for during an investigation.
The poster covers GitHub, GitLab, Bitbucket and Azure DevOps, chosen as the four most common version control platforms across Wiz customers.
GitHub retains Git read/write events for only 7 days by default.
Standard GitLab configurations do not save Git operations to the database at all, making these events unavailable unless log streaming is preconfigured.
88% of Wiz customers rely on SaaS version control solutions, which frequently abstract away the raw API requests sent to the server.
GitHub is currently the only one of the four hosted platforms that allows organisations to log API requests, and doing so requires explicit configuration and log streaming.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific but single-source and vendor-authored
The claims are unusually concrete for a vendor post: named platforms, a numeric default retention window, a named configuration gap, and a customer-base percentage. But the cluster contains exactly one source, and that source is the vendor's own blog with no citation to platform documentation, no effective dates for the stated defaults, and no external corroboration of the retention, API-logging or license-tier assertions. The poster itself, which holds the per-platform table and event names, is not part of the supplied material.
Guidance shipped, uptake unmeasured
There is a dated release of the poster and a vendor telemetry disclosure that 88% of Wiz customers run SaaS version control, which establishes the exposed population. There is no evidence of anyone adopting the checklist, enabling the streaming or metadata settings, or of the poster changing an investigation outcome, so adoption is limited to publication plus a stated customer base.
Facts land; the product pitch outruns them
The technical core is stated soberly and is checkable, so the story is close to aligned there. The overstatement is concentrated in the recommendation layer: CDR is asserted to ingest cloud-scale volumes and correlate SaaS context 'without the cost and operational overhead of a legacy SIEM' with no comparison data, by a vendor that sells CDR. The 'increasingly target' trend framing and the TeamPCP reference also carry no supporting counts.
Vendor documents a gap its product fills
Wiz is a security vendor publishing free DFIR guidance that concludes with a recommendation to send the telemetry to a Cloud Detection and Response platform, the category Wiz sells, framed explicitly against legacy SIEM cost. The customer-base statistic is also self-reported. The incentive is transparent rather than hidden, and the platform-specific configuration advice is useful regardless of destination, but the commercial alignment between the diagnosed gap and the suggested remedy is direct.
Plausible and specific, unverified and unreplicated
Confidence is moderate: the operational claims are the kind a specialist IR team would get right and are stated precisely enough to be checked, which supports the story's central point that late-discovered repository compromises outlive default Git event retention. It is held down by total dependence on one interested publisher, absence of the poster's own data table from the supplied material, and no independent confirmation of the retention defaults or license-tier gating that the practical recommendation rests on.
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
security
Perth charges leave the TeamPCP rotation list exactly where the FBI left it on July 22 distinct publishers
build
Your scanner finds it in seconds; the average fix now takes 252 days1 distinct publisher
security
AFP arrests two Western Australians tied to the Shai-Hulud supply chain spree1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026