GitHub actions crossing private-to-public exposure boundary
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
Microsoft Sentinel (KQL)

