Does anyone know what to look for in the github audit logs, exactly?
Try here: https://github.com/settings/security-log
/settings/audit-log" rel="nofollow">https://github.com/organizations//settings/audit-l...
... but the real question is what would malicious activity look like, exactly?